Two new logical flaws in Kerberos just dropped at Black Hat. Low-privileged user to full domain takeover, including domain admins.
If you're doing Active Directory pentesting, Kerberos attacks, red teaming, identity security, or detection engineering, read this.
KerberLoss (CVE-2026-25177) and ResetNightmare (CVE-2026-27912). Both are logical bugs, not memory corruption. Described as surprisingly easy to exploit.
https://t.co/dgJC3JHjOf
#Infosec #RedTeam #DetectionEngineering
OpenAI & Anthropic: “look at how powerful our agentic systems are we breached multiple companies computer systems!”
Companies who were breached: “we are pressing charges for their violation of the Computer Fraud and Abuse Act”
OpenAi & Anthropic: