Aller au contenu
Wednesday, August 5, 2026

B-EMPIRE

Culture without borders. / La culture sans frontières.

The Vulnerability Shaking Black Hat: Why Active Directory is a Global Urgency for Businesses

Two vulnerabilities presented at Black Hat USA expose the core of enterprise networks: KerberLoss can cause a denial of service and force a downgrade to NTLM, while ResetNightmare opens a path for privilege escalation to the most sensitive accounts.


Cheventong Vil
Cheventong Vil
August 5, 2026  ·  5 min de lecture
La faille qui secoue Black Hat : pourquoi Active Directory devient l’urgence mondiale des entreprises
B-EMPIRE Magazine

The digital heart of thousands of businesses is under the spotlight at Black Hat USA 2026. Two vulnerabilities affecting Kerberos and Microsoft Active Directory, dubbed KerberLoss and ResetNightmare, demonstrate that a user with low privileges can threaten an entire infrastructure. One allows for a denial of service and pushes authentication back to NTLM, an older protocol. The other can open a pathway to the compromise of highly privileged accounts. For international groups as well as French SMEs, the signal is impossible to ignore.

Presented this Wednesday, August 5, in Las Vegas by researcher Shai Laron from Semperis, the two vulnerabilities are not a distant theoretical scenario. They target Active Directory, the directory that organizes identities, rights, and access to resources in a vast portion of the professional world. When an Active Directory domain falls, it is not just a few workstations that are affected: business applications, servers, data, backups, and administrative accounts can all be drawn into the crisis.

KerberLoss: The Mechanism That Can Weaken Authentication

Kerberos is designed to allow users and machines to prove their identity without constantly transmitting their password. In a Windows environment, it is a crucial piece of trust among the various components of the network. KerberLoss, referenced as CVE-2026-25177, circumvents a security mechanism applied at the forest level of Active Directory, according to Semperis.

The potential outcome is twofold. An attacker can disrupt the functioning of the domain, but can also force a downgrade from Kerberos to NTLM. This switch matters because NTLM relies on an older architecture and is associated with numerous scenarios of relay or credential theft. A defense built around the idea that Kerberos always protects exchanges can thus lose some of its robustness precisely when the attacker seeks to advance.

ResetNightmare: From a Regular Account to the Highest Privileges

ResetNightmare, identified under the reference CVE-2026-27912, poses an even more spectacular threat. The bulletin from the National Vulnerability Database describes an incorrect authorization in Windows Kerberos that allows an authorized attacker to escalate their privileges on an adjacent network. The assessment indicates a high impact on confidentiality, integrity, and availability.

Semperis explains that a low-privileged user can exploit this logic to compromise other accounts, including domain administrators. This does not mean that every Windows computer is automatically hacked. Prior access to the targeted context and specific conditions are required. However, in many intrusions, obtaining a first standard account is just the beginning. The ability to transform this entry point into domain control completely changes the scale of risk.

Why the Black Hat Revelation Changes the Perception of Danger

The two CVEs were already documented in vulnerability databases and had been subject to Microsoft patches. However, the Black Hat presentation brings a decisive element: it links the vulnerabilities to a comprehensible and reproducible attack chain. The official conference program places identity, trust, and control among the major themes of this edition, alongside risks related to GPUs, Unicode, and software supply chains.

A vulnerability often attracts little attention as long as it remains described in a technical bulletin. Once researchers publicly expose its logic, prerequisites, and impact, the reaction window narrows. Defenders gain a better understanding of the danger, but attackers also receive new insights. The appropriate response is therefore not panic: it is an accelerated and documented verification of patches.

Windows Server: The Versions Teams Must Check

The NVD lists several generations of Windows Server for ResetNightmare, including 2012, 2012 R2, 2016, 2019, 2022, the 23H2 edition, and Windows Server 2025 before certain corrected build levels. However, organizations should not rely on a simple list read on the internet. They must compare their actual inventory with the Microsoft advisory corresponding to the CVE, check installed cumulative updates, and confirm that domain controllers have indeed restarted when required.

This step is particularly important in hybrid environments. Many businesses use modern cloud services while maintaining an old on-premises Active Directory connected to multiple applications. A forgotten server, a poorly inventoried subsidiary, or a domain controller maintained for a legacy application can be enough to preserve a critical attack surface.

The Immediate Action Plan for French Businesses

The priority is to inventory all domain controllers and verify the patches associated with CVE-2026-25177 and CVE-2026-27912 in the Microsoft security guide. Managers should then look for unusual NTLM authentications, monitor resets of sensitive accounts, and examine abnormal Kerberos events. Administrative accounts should be separated from daily use, protected by dedicated workstations, and subjected to enhanced monitoring.

It is also essential to test the restoration of Active Directory. An untested backup is not a guarantee. French and European teams, already subject to increasing requirements with NIS2 and DORA depending on their sector, must be able to demonstrate that they know how to isolate a compromise, rebuild a trusted domain, and maintain their essential functions. The stakes go beyond compliance: a compromised identity can render many other security investments useless.

The Signal That Leaders Can No Longer Delegate

Active Directory is sometimes perceived as technical plumbing reserved for system administrators. KerberLoss and ResetNightmare remind us that it is, in fact, a strategic asset. A failure or takeover of the domain can halt production, block payments, prevent employees from logging in, and open access to confidential information. The risk becomes financial, legal, and reputational.

The revelation from Black Hat 2026 does not state that all companies will be attacked tomorrow. It asserts something more useful: organizations that have delayed their updates, neglected their old servers, or retained excessive privileges now have less time to correct their trajectory. The world is watching the demonstrations in Las Vegas; responsible teams must, in turn, look at their own logs, server versions, and recovery capabilities.

Sources

Vous êtes hors ligne. Voici les derniers articles disponibles.