Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
IT Security NachrichtenKI-Coding-Agenten leaken über 13.000 interne Screenshots auf GitHub(30.09.2026 um 15:22 Uhr)
•
IT Security NachrichtenIT Security News Hourly Summary 2026-09-30 15h : 13 posts(30.09.2026 um 15:00 Uhr)
•
IT Security NachrichtenDon’t Make It Easy For Them: Cybersecurity Awareness Month 2026(30.09.2026 um 15:01 Uhr)
•
IT Security NachrichtenTrump, Six AI Giants Sign ‘Super Intelligence’ Safety Accord(30.09.2026 um 15:02 Uhr)
•••
IT Security NachrichtenHow to Use Cyber Risk Quantification to Justify Security Budgets(30.09.2026 um 15:19 Uhr)
•
IT Security NachrichtenTrump, Six AI Giants Sign 'Super Intelligence' Safety Accord(30.09.2026 um 15:00 Uhr)
•
Sicherheitslücken (CVE)WatchGuard Patches Critical Fireware OS Code Injection Vulnerability(30.09.2026 um 15:16 Uhr)
••
IT Security NachrichtenKI-Coding-Agenten leaken über 13.000 interne Screenshots auf GitHub(30.09.2026 um 15:22 Uhr)
•
IT Security NachrichtenIT Security News Hourly Summary 2026-09-30 15h : 13 posts(30.09.2026 um 15:00 Uhr)
•
IT Security NachrichtenDon’t Make It Easy For Them: Cybersecurity Awareness Month 2026(30.09.2026 um 15:01 Uhr)
•
IT Security NachrichtenTrump, Six AI Giants Sign ‘Super Intelligence’ Safety Accord(30.09.2026 um 15:02 Uhr)
•••
IT Security NachrichtenHow to Use Cyber Risk Quantification to Justify Security Budgets(30.09.2026 um 15:19 Uhr)
•
IT Security NachrichtenTrump, Six AI Giants Sign 'Super Intelligence' Safety Accord(30.09.2026 um 15:00 Uhr)
•
Sicherheitslücken (CVE)WatchGuard Patches Critical Fireware OS Code Injection Vulnerability(30.09.2026 um 15:16 Uhr)
••
Intelligence View
⚡ tsecurity.de Intelligence

Black Hills Information Security: Something Wicked This Way Enrolls: Abusing ADCS with ESC17

Video von Black Hills Information Security auf YouTube: 🔗 Register for this FREE Infosec webcast and more! – https://poweredbybhis.com Active Directory…

HD Video
Something Wicked This Way Enrolls: Abusing ADCS with ESC17
Video abspielen
0
↗ Quelle (Black Hills Information Security)
Reagiere als Erste:r — dein Feedback zählt!

YouTube Video

🔗 Register for this FREE Infosec webcast and more! –

https://poweredbybhis.com



Active Directory Certificate Services misconfigurations continue to give attackers powerful privilege escalation paths, sometimes allowing low privileged accounts to reach Domain Administrator. Hardening efforts often focus on removing dangerous EKUs such as Client Authentication from certificate templates, but Server Authentication is frequently left behind.



Join Alyssa Snow and Kaitlyn Wimberley, Security Consultants at Black Hills Information Security, for a free one-hour webcast exploring ESC17, a newly documented ADCS escalation technique.



ESC1 taught us that Enrollee-Supplied Subject on a misconfigured template could lead directly to domain compromise. ESC17 demonstrates that the same primitive creates an entirely different attack path when paired with the Server Authentication EKU. Users with enrollment rights can obtain legitimately issued, domain-trusted TLS certificates for arbitrary internal hostnames (including critical infrastructure such as a WSUS server) and impersonate TLS-protected services provided by those hosts.



We’ll walk through a complete attack chain from a low privileged domain user to SYSTEM level execution on targeted domain-joined workstations. No initial administrative privileges. No software vulnerability required. Just a misconfigured template, a trusted certificate, redirected traffic, and an update that definitely came from Microsoft.



Chat with your fellow attendees in the Black Hills Infosec Discord server:

https://discord.gg/BHIS

in the #🔴live-event-chat channel.

2. Cyber Threat Intelligence & Forensik

CTI Threat Relationship Graph5 Knoten / 4 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
MITRE ATT&CK Matrix Navigator 14 Taktiken
1 belegte TechnikenLive-Mapping
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-92870 | A stack-based buffer overflow vulnerability exists in Pgpool-II, which m…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag