:

CERTIGHOST POC EXPLOIT TARGETS WINDOWS DOMAINS

AI DESK1 MIN READ
MON, JUL 27, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A proof-of-concept exploit for Certighost, a Windows Active Directory Certificate Services vulnerability, has been released. Authenticated attackers can use it to potentially compromise entire Windows domains.

Certighost affects Windows Active Directory Certificate Services (AD CS), a critical component used by most enterprise networks for authentication and encryption. The vulnerability allows attackers with valid domain credentials to escalate privileges and take control of certificate issuance processes. The PoC exploit's release increases the risk for organizations that have not patched their systems. Windows domains rely on AD CS to verify user and device identities, making compromise particularly severe—attackers gaining control could impersonate any user or device on the network. Microsoft has released patches addressing Certighost as part of recent security updates. Security teams should prioritize patching AD CS servers and reviewing certificate issuance logs for suspicious activity. Organizations should also audit user access to certificate services and enforce additional authentication controls. The vulnerability underscores the importance of timely patching for directory services infrastructure, as compromise can provide attackers with persistent domain-wide access.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A threat actor compromised BdThemes' infrastructure and modified a remote JSON feed to create unauthorized admin accounts on affected WordPress sites. The attack leveraged the company's premium web-design plugin distribution system.

7H AGOAI Desk

HackerOne, the bug bounty platform, has come under criticism following recent policy shifts and operational decisions that have impacted its security researcher community.

8H AGOSecurity Desk

Simply deleting files from old USB drives before disposal provides minimal data protection. Experts warn that deleted data can be recovered with basic tools, making proper wiping essential.

11H AGOIndustry Desk

CISA has confirmed that ransomware groups are actively exploiting two recently patched vulnerabilities in SonicWall SMA1000 devices, including a critical server-side request forgery flaw.

13H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.