📰 IT Security NachrichtenHow A.I. Risks Are Splitting Silicon Valley and Washington(16.09.2026 um 03:24 Uhr)
📰 IT NachrichtenToday’s NYT Connections Hints and Answers for Sept. 16, #1193(16.09.2026 um 02:48 Uhr)
💾 IT Security Toolsmacnoise v1.0.0(16.09.2026 um 01:45 Uhr)
🔧 AI Nachrichten Rubrics-as-an-Attack-Surface(16.09.2026 um 02:15 Uhr)
🔧 AI Nachrichten INTACT(16.09.2026 um 02:45 Uhr)
📰 IT Security NachrichtenHow A.I. Risks Are Splitting Silicon Valley and Washington(16.09.2026 um 03:24 Uhr)
📰 IT NachrichtenToday’s NYT Connections Hints and Answers for Sept. 16, #1193(16.09.2026 um 02:48 Uhr)
💾 IT Security Toolsmacnoise v1.0.0(16.09.2026 um 01:45 Uhr)
🔧 AI Nachrichten Rubrics-as-an-Attack-Surface(16.09.2026 um 02:15 Uhr)
🔧 AI Nachrichten INTACT(16.09.2026 um 02:45 Uhr)

📰 IT Security Nachrichten 🕛 vor 8 Jahren 9 Min Lesezeit SECURITY-FEED
0

A Massive Cyber Breach at a Company Whilst it was Considering the 'Cloud'

↗ Quelle (cyber-security-blog.com)
🗣️ Stimme:
(A Must-Read for all CEOs, CFOs, CIOs, CISOs, Board Members & Shareholders Today)


Folks,

Today was supposed to be an exciting Friday morning at a Multi-Billion $ organization since the world's top Cloud Computing companies were going to make their final pitches to the company's C-Suite today, as it was considering moving to the "Cloud."

With Cloud Computing companies spending billions to market their latest Kool-Aid to organizations worldwide (even though much of this may actually not be ready for mission-critical stuff), how could this company too NOT be considering the Cloud?



The C-Suite Meeting

Today was a HUGE day for this multi-billion dollar company, for today after several months of researching and evaluating their choices and options, the company's leadership would finally be deciding as to which Cloud Computing provider to go with.


He then gathered himself and proceeded to request everyone except the C-Suite to immediately leave the conference room.

He told the Vice President of this Cloud Computing company - "Hopefully, we'll get back to you in a few weeks."

He then looked at the CEO and the Chairman of the Board, and he said - "Sir, we have a problem!"




Its Over

The CEO asked the CIO - "What's wrong? What happened?"

The CIO replied - "Sir, about 30 minutes ago, an intruder compromised the credentials of each one of our 20,000 employees!"

to basically request and instantly obtain the credentials of every single user from our foundational Active Directory deployment."

of our cyber security"

The CEO then asked - "Wait. Can just anyone request and extract credentials from Active Directory?"

The CISO replied - "Sir, not everyone can. Only those individuals whose have sufficient access to do so, and by that I mean, specifically only those who have Get-Replication-Changes-All

The CEO was furious! - "You're kidding right?! Microsoft's spent billions on this new fad called the "Cloud", yet it doesn't even have a solution to help figure out something as vital as this in Active Directory? How long has Active Directory been around ?!

The CISO replied - "Seventeen years."

The CEO then said in disbelief - "Did you just 17 years, as in S-E-V-E-N-T-E-E-N years?!  Get Satya Nadella on the line now! Perhaps I should #REFRESH his memory that we're a customer, and that we may have just lost a few B-I-L-L-I-O-N dollars!"




This is for Real

Make NO mistake about it. As amusing as it might sound, the scenario shared above is very REAL, and in fact today, most business and government organizations worldwide that operate on Active Directory have no idea as to exactly who has sufficient effective permissions to be able to replicate secrets out of their Active Directory. None whatsoever!

in their foundational Active Directory deployments.

its customers about the importance of is just the . Today most organizations are likely , and thus about exactly who can create, delete and manage the entirety of their domain user accounts, domain computer accounts, domain security groups, GPOs, service connection points (SCPs), OUs etc. even though every insider and intruder could try and figure this out and misuse this insight to compromise their security.

Technically speaking, with even just minimal education and the right tooling, here is how easy it is for organizations to figure this out and lock this down today, i.e. to lock this down before an intruder can exploit it to inflict colossal damage -

All of this could've been prevented, if they only , and had the ability to determine excessive it takes.

organization today.

Best wishes,
, ,   .



PS2: Note for Microsoft - This may be the simplest example of ", which embodies the technical brilliance of a certain Mr. , which embodies the technical expertise of a certain former Microsoft employee, may be the simplest example of how one could defend Active Directory ACLs by being able to instantly identify/audit effective permissions/access in/across Active Directory, and thus lockdown any and all unauthorized access in Active Directory ACLs, making it impossible for an(y) unauthorized user to use Mimikatz DCSync against Active Directory.



PS3: They say to the wise, a hint is enough. I just painted the whole picture out for you. (You may also want to read .)

PS4: If you liked this, you may also like - How To Easily Identify & Thwart Sneaky Persistence in Active Directory
Vollständiges Original-Advisory
Ausführliche Details, Exploit-Analyse & Hersteller-Stellungnahme auf cyber-security-blog.com.
↗ Original-Artikel auf cyber-security-blog.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Außer der Reihe: Microsoft fixt Probleme und Lücken nach Windows-Updates | heise online
1 Quelle
Today’s NYT Connections Hints and Answers for Sept. 16, #1193
1 Quelle
Interlune raises $5M for initiatives that go beyond mining the moon
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten A Massive Cyber Breach at a Company Whilst it was Considering the 'Cloud'

Thematisch verwandte Begriffe: Massive, Cyber, Breach, Company · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...