Certighost (CVE-2026-54121): A Public Exploit Now Exists for This AD CS Domain Controller Impersonation Flaw A public proof-of-concept exploit is now available for CVE-2026-54121, nicknamed “Certighost,” a critical Active Directory Certificate Services vulnerability that lets... Sep 23, 2026 5 min read Active Directory / Security
VMSA-2026-0006.1: Critical vCenter Auth Bypass and ESXi VM Escape Flaws You Need to Patch Now Broadcom’s VMSA-2026-0006.1 advisory patches a set of critical VMware vCenter and ESXi vulnerabilities, two of them with a maximum CVSS... Sep 19, 2026 5 min read Security / Virtualization
Kerberoasting in 2026: What CVE-2026-20833 and RC4 Disablement Actually Change for Active Directory If any service accounts in your Active Directory environment are still relying on RC4 for Kerberos ticket encryption, Microsoft’s phased... Sep 18, 2026 5 min read Active Directory / Security
Microsoft Entra Conditional Access Custom Controls Are Retiring: Migrating to External MFA Before September 30, 2026 Microsoft is retiring Custom Controls in Microsoft Entra Conditional Access. Creating new Custom Controls or editing existing ones stops working... Sep 16, 2026 5 min read Active Directory / Azure / Security
September 2026 Patch Tuesday: What Windows Server, Active Directory, and Exchange Admins Need to Patch Right Now Microsoft’s September 2026 Patch Tuesday is the largest release in the program’s history: 974 CVEs addressed in a single month,... Sep 15, 2026 6 min read Active Directory / Exchange / Security
The Security Standards Every Sysadmin Should Actually Know: NIST, ISO 27001, CIS, OWASP, and MITRE ATT&CK Security work references a specific, small set of standards bodies constantly, in audits, in compliance requirements, and in the hardening... Sep 7, 2026 3 min read Security
Tracing a Domain Compromise: Key Active Directory Logs and Indicators of Compromise to Check First Golden Ticket and DCSync indicators, GPO tampering, AdminSDHolder ACL abuse, SID History injection, and domain controller logon anomalies to check first when AD itself is suspected of compromise. Sep 6, 2026 4 min read Active Directory / Security
How to Investigate a Compromised Exchange Server: A Practical Incident Response Checklist (Exchange 2016/2019) The exact checklist for triaging a suspected Exchange compromise: web shell locations, IIS log indicators, mailbox export/permission abuse, transport rule tampering, and what to preserve before remediating. Sep 6, 2026 4 min read Exchange / Security
Auditing MFA Registration Across Microsoft 365 with Microsoft Graph PowerShell If you’re still running Get-MsolUser to check MFA status, that module is deprecated and no longer receiving updates, Microsoft has... Dec 13, 2025 3 min read Cloud Computing / Microsoft / Security
Kerberos Encryption Protocols: Security Standards Alignment This document aligns with Microsoft security best practices, NIST SP 800-63B, ISO/IEC 27001 Annex A.9.4, and CIS Windows Server benchmarks.... Oct 17, 2025 27 min read Active Directory / Microsoft / Security / Windows Server