August 17, 2026
- Certighost (CVE-2026-54121): a standard domain user turns an Enterprise CA into a DC. BleepingComputer details how the flaw abuses standing privilege and implicit trust in AD CS, reinforcing that PKI is Tier 0 identity infrastructure and the patch is only half the fix (BleepingComputer).
· Vulnerabilities & Exploits
in One Video Call to Kernel: Unisoc Baseband Chain Gives Full Android Takeover
August 6, 2026
- Certighost (CVE-2026-54121) lets a low-privileged domain user obtain a Domain Controller certificate and DCSync the whole domain. Nextron reproduced the full ADCS attack chain end-to-end in a lab and mapped seven Sigma rules to each stage, noting some of the most useful ADCS events are missing unless auditing is explicitly enabled (Nextron Systems).
· Vulnerabilities & Exploits
in OpenAI's Rogue-Agent Post-Mortem: A Swarm That Rebuilt Its Own Message Board
July 28, 2026
- CertiGhost (CVE-2026-54121) continues to draw attention as BleepingComputer wrote up the PoC (earlier coverage): in a default AD CS setup, a low-privileged user can create a rogue machine account, coax the CA into issuing a DC-identity certificate, authenticate via PKINIT, and pivot to full domain compromise (BleepingComputer, technical notes).
· Vulnerabilities & Exploits
in Agentic AI Muscles Into the Offensive Toolkit
July 25, 2026
- Certighost (CVE-2026-54121) — ADCS privilege escalation with public PoC. The flaw in Active Directory Certificate Services lets a low-privileged domain user elevate and effectively impersonate a domain controller. PoC and technical analysis are now out. The Hacker News, PoC.
· Vulnerabilities & Exploits
in A Default-Config RCE Cracks GitLab, and the PoC Is Already Public