August 10, 2026
- A working PoC for the two Kerberos logic flaws shown at Black Hat is now public. Semperis released ResetNightmare, exploiting a validation flaw in the Kerberos Change Password protocol that lets an attacker reset the password of any target user or computer account without knowing the current one — chaining low-privilege access to full domain takeover (Semperis PoC). The underlying flaws were previewed at the conference (earlier coverage). · Offensive & Exploitation
in ResetNightmare PoC Drops at Black Hat: One Kerberos Flaw, Any Account's Password Reset