Security Update Backfires: Windows 11 Patch Breaks Domain Trust, Locks Out Enterprise Users
Microsoft is investigating reports that the September Windows 11 cumulative update, KB5124008, is breaking Active Directory domain trust on some enterprise machines, blocking valid logins. The likely cause...
Attackers Are Quietly Cloning Domain Controllers’ Password Database — Then Deleting the Evidence
Incident responders at Huntress have documented a stealthy attack pattern in which intruders use Windows' own shadow-copy tooling to clone and steal the Active Directory password database, then...
AI Agent Swarm Exploits PaperCut Flaws Across 440 Servers Worldwide
A Russian-speaking operator used hundreds of autonomous AI agents to compromise 440 PaperCut servers across 48 countries. Although only a fraction reached domain administrator, the campaign shows how...
Ransomware Affiliate Used AI Coding Tool Cursor to Plan Attacks on 20+ Companies Across 9 Countries
An exposed staging server has given researchers an unusually detailed look at how a Russian-speaking Aurora ransomware affiliate used the AI coding assistant Cursor to help plan and...
Certighost Flaw Let Ordinary Users Impersonate Domain Controllers and Seize Active Directory
A newly patched Active Directory Certificate Services bug, dubbed Certighost, let any low-privileged domain user trick a certificate authority into treating a rogue machine as a real Domain...
This Week’s Threat Landscape: Patch Tuesday’s 570 Fixes, an Active Directory Zero-Day, and AI Tools Under Fire
A packed week in cybersecurity saw Microsoft ship roughly 570 patches including two actively exploited zero-days, a WordPress RCE bug threatening hundreds of millions of sites, and a...
Threat Actors Use AI Agents and Cursor IDE to Automate Active Directory Attacks and Beat EDR
Sophos has uncovered a Russian-speaking threat actor using AI-assisted tools, Cobalt Strike, and a purpose-built automated lab to develop EDR bypass malware targeting Active Directory environments — with...
CVE-2026-41089: Windows Netlogon 0-Click RCE Now Actively Exploited — Patch Domain Controllers Immediately
Microsoft’s May 2026 Patch Tuesday addressed CVE-2026-41089, a critical Windows Netlogon 0-click RCE — now actively exploited in the wild. Domain controllers running unpatched Windows Server face complete...