You can also use Shodan's Certificate Transparency (CT) API to enumerate a target's subdomains directly from the https://t.co/b8sFqTyruD database.
https://t.co/6vL6HjRSmi
/api/v1/domain/{domain} ~returns the certificates that match a domain
/api/v1/domain/{domain}/hostnames ~returns all hostnames associated with a domain
CVE-2026-54121 (Certighost) enables authenticated low-privileged users to escalate privileges through Microsoft AD CS, potentially leading to full Active Directory compromise.
This repository provides a technical analysis of the vulnerability, attack chain, exploitation prerequisites, detection opportunities, mitigation guidance, and a PoC implementation for authorized security testing.
https://t.co/wiJalC6EyM
We found a gadget-free RCE in Fastjson 1.2.83 - the final release of the 1.x line, and still one of the most widely-deployed Java JSON libraries in production today, even with 2.x around.
No classpath gadget. One payload-> RCE.