Active Directory Security25 July 2026
Certighost (CVE-2026-54121): Any Domain User Could Impersonate a Domain Controller
A public exploit shows how a certificate-enrollment fallback in AD CS let any authenticated domain user forge a Domain Controller identity and pull the krbtgt secret via DCSync.
active-directoryad-cscve-2026-54121
4 min readRead
Windows Internals / Offensive Security5 July 2026
GetProcessHandleFromHwnd: How One Windows API Enabled a Persistent UAC Bypass
Google Project Zero traces a public Quick Assist UAC bypass back to a poorly documented Win32 API that Microsoft only half-fixed in 2023 — and shows why fully protected processes stayed exploitable until Windows 11 24H2.
windows-securityuac-bypassprivilege-escalation
5 min readRead