Resetting compromised passwords in Active Directory doesn't automatically remove attackers from the system. Cached credentials and Kerberos tickets can allow unauthorized access to persist even after password changes.
When Active Directory accounts are compromised, organizations typically reset passwords as a first response. However, this standard remediation step has a critical weakness: attackers can remain authenticated through cached credentials and Kerberos tickets.
Cached credentials—stored locally on machines—remain valid even after a password reset, allowing attackers to maintain access on previously compromised endpoints. Similarly, Kerberos tickets issued before the password change continue to function until they expire, which can take hours or days depending on configuration.
Specops Software notes that attackers leveraging these mechanisms can operate undetected within the network despite password changes. Organizations need additional steps beyond resets to fully remediate breaches, including invalidating active sessions, clearing cached credentials across affected systems, and reviewing Kerberos ticket-granting tickets.
The findings underscore that comprehensive incident response requires multiple layers of action rather than relying on password resets as a standalone solution.
Security researchers have identified potential hardware backdoors in certain x86 processors. The findings, detailed in a GitHub repository called Rosenbridge, reveal vulnerabilities at the processor level that could allow unauthorized access.
Flock Safety, the traffic camera company, is expanding beyond law enforcement with plans to deploy dashcams in rideshare vehicles and offer coaching services to police departments.
A sharp rise in explicit deepfake images of UK children has been reported by an online safety service, as authorities warn that AI tools are making the creation of sexualized or 'nudified' content increasingly accessible.
Gen's latest threat report details two distinct attack campaigns exploiting compromised email accounts and clipboard manipulation to steal from businesses and cryptocurrency users.