HackerFeeds

CyberSecurity News

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

The Hacker News
· July 24, 2026

AI summary

Researchers have published a working exploit for a flaw, dubbed Certighost, that allows a low-privileged Active Directory user to obtain a certificate for a Domain Controller and authenticate as that machine. This exploit enables the user to retrieve the krbtgt secret through DCSync, as Domain Controller accounts have directory replication rights. The exploit was made public by researchers H0j3n and Aniq Fakhrul. The resulting Kerberos credential can be used to impersonate the Domain Controller. The vulnerability can be leveraged by low-privileged users, making it a significant concern. The exploit was published on July 24.

Read the full article at The Hacker Newsthehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.