August 11, 2026
- The two Black Hat Kerberos logic flaws are now weaponized against Linux and NetExec. A full write-up walks through exploiting ResetNightmare (CVE-2026-27912, a Change Password protocol flaw enabling any account's password reset via UPN spoofing) and KerberLoss (CVE-2026-25177, service impersonation) from a Linux box to full domain takeover (cravaterouge), building directly on last week's PoC drop (earlier coverage). · Vulnerabilities & Exploits
in Metabase Zero-Day Blast Radius Widens to LexisNexis and Framework