Starting today, 3PM GST: Chris Cochran on the AI Security Maturity Model, Gulf Region Edition. Join soon or grab the ebook.
Register: https://t.co/Q7iHZOF42o | Ebook: https://t.co/wRI05JoyHF
In H1 2026, #ESETresearch analyzed 900,000 agentic AI skills – add-ons providing instructions that teach agents how to perform specific tasks – and found 25,000 suspicious ones and more than 3,000 outright malicious. 1/6
CertiGhost (CVE-2026-54121) deserves much more attention than it is getting right now, from my point of view.
In a common/default AD CS setup, a low-privileged domain user can create a rogue machine account, trick the CA into issuing a certificate with the identity of a Domain Controller, authenticate as that DC via PKINIT, gain replication access and basically compromise the whole domain.
So if you run on-prem Active Directory with AD CS and your CA is still unpatched, an ordinary domain user may currently have a path to the highest privileges in your domain.
Patch it, obviously, or apply the temporary mitigation. But if you patched only recently, the harder and from my point of view more important question is: did someone already exploit it?
A patch closes the hole. It does not unfuck a domain that was already compromised.
I put a list of things I would check in the first reply.
Overview:
https://t.co/NHaJD5hlFi
Technical details:
https://t.co/ucGrc2SLbJ
PoC:
https://t.co/nvWARPtmso
Microsoft advisory:
https://t.co/kYoXWRKTyz
Temporary mitigation:
https://t.co/hVOHBYO5hD
👻Certighost (CVE-2026-54121) Detection
A newly disclosed Active Directory Certificate Services (AD CS) vulnerability, dubbed Certighost, allowed a low-privilege domain user to impersonate a Domain Controller and take over an entire Active Directory domain.
https://t.co/y8yZbZgsSZ
👇 A Sentinel KQL to help detect AD CS abuse.
https://t.co/bGrHkbHEK4
#Cybersecurity #Certighost #ThreatHunting
The lesson is not that AI attackers require AI defenders. AI can help process telemetry and reconstruct a large incident, but this compromise progressed because basic containment, sandboxing, rate limiting, credential isolation and network segmentation were insufficient.
With proper controls, the agents should have been throttled or contained long before anyone needed an LLM to analyze 17,000 attacker actions.
🚨 New on Predicta Search
Search any username and view all modifications made to the associated Twitter account
➡️ Test it for free at https://t.co/phrmLUHA31
Resources like this are super helpful but man does it show how ridiculous infosec certs have gotten 350 certs from almost 60 vendors many over $1,000
https://t.co/7xaRMsK4E7
[watch][NIS2]
Dernier papelard de Wallix sur NIS2: https://t.co/CIUiSI97vj
Intéressant, mais certainement dommage de mélanger les concepts de menace interne (insider threat) et cyber-attaque via la chaîne de sous-traitance (supply-chain attack)... :(
Metrics as a Skill, Not a Report. 🧠
Most SOCs collect metrics. Few actually use them to improve performance.
If you’re tracking MTTD, MTTR, or alert volume but still feel stuck, the issue isn’t the tooling; it’s the interpretation. 📊
This guide breaks down:
✅ Which SOC metrics actually matter?
✅ How to measure them correctly (not vanity numbers)?
✅ How to turn metrics into real workflow upgrades?
👉 Read the full SOC Metrics guide: https://t.co/ocUustWEft
#CyberDefenders #SOC #Cybersecurity #SIEM
𝗠𝗮𝗹𝗶𝗰𝗶𝗼𝘂𝘀 𝗨𝗥𝗟 𝗣𝗿𝗼𝘁𝗲𝗰𝘁𝗶𝗼𝗻 𝗶𝗻 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗧𝗲𝗮𝗺𝘀
The feature 'Malicious URL Protection' is in preview.
Turn off or turn on Link Protection through Teams Admin Center (See below)
What's the difference between this feature and Safe Links for Teams in Microsoft Defender for Office 365?
1. This feature is available for all Teams users as part of base protection.
2. Safe Links acts at the time of URL click and blocks the URL based on your settings in the Microsoft Defender portal.
#Cybersecurity #MicrosoftTeams #MaliciousURLProtection
🚨 CVE-2025-6543 is actively exploited in the wild.
Found multiple vulnerable NetScaler instances exposed online.
Update your Citrix ADC now!🛡️
https://t.co/GL2PsoTXyQ
#Citrix#NetScaler#CVE2025#CyberSecurity
🚨 Alert: CVE-2024-12084 🚨
A severe heap overflow vulnerability in rsync could lead to remote code execution—affecting 600k+ systems globally.
🔎 Read more details on the Falco detection rule for this CVE, as well as steps for mitigation from Sysdig TRT:https://t.co/aKe5J8bwxx