TGViewer
Fsecurity | HH Fsecurity | HH @hellohackingteam · 2.06K subscribers
Post #7970 133

Forwarded from 1N73LL1G3NC3

ResetNightmare

ResetNightmare (CVE-2026-27912) is a validation flaw in the Kerberos Change Password protocol that allows for resetting the password of any target user/computer account, without knowing the current one. The attack requires an unpatched domain controller, and the ability to write a userPrincipalName (UPN) on any account you control. Alternatively, the vulnerability can also be abused by an attacker having the ability to create new users/computers in any OU, as creating a user/computer allows you to get GenericWrite permissions over it.

Blog: Identity Crisis: Novel Vulnerabilities Leading to Kerberos Downgrade, DoS, and Full Domain Takeover
More from @hellohackingteam
  1. Oct 5, 2026Реверс-инжиниринг червя Win32.Mydoom.A (Novarg) Аналитики разобрали архитектуру сетевого ч…
  2. Oct 5, 2026🔗 Ссылка: https://github.com/An0nUD4Y/AV-EDR-Lab-Environment-Setup
  3. Oct 5, 2026🔗 Ссылка: https://opennet.me/66389/
  4. Oct 4, 2026Как тренируются red team: один день из жизни атакующих на киберполигоне Участие в битве St…
  5. Oct 4, 2026Discord сервер 👆🏻Тут можно пообщаться и найти много полезной информации 🦈
  6. Oct 4, 2026Post #8152
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →