<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Active Directory</title><description>Cybersecurity articles tagged #Active Directory on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Certighost Exploit: Domain Controller Impersonation via Active Directory Certificates</title><link>https://runtimerebel.com/blog/certighost-exploit-domain-controller-impersonation-via-active-directory-certificates</link><guid isPermaLink="true">https://runtimerebel.com/blog/certighost-exploit-domain-controller-impersonation-via-active-directory-certificates</guid><description>The Certighost exploit enables low-privileged Active Directory users to obtain domain controller certificates, authenticate as DCs, and retrieve the krbtgt secret for…</description><pubDate>Fri, 24 Jul 2026 17:40:50 GMT</pubDate><category>Certighost</category><category>Active Directory</category><category>Domain Controller</category><category>Privilege Escalation</category><category>DCSync</category><category>Kerberos</category><category>Certificates</category></item><item><title>Microsoft Zero-Days: Active Directory &amp; SharePoint Exploited</title><link>https://runtimerebel.com/blog/microsoft-zero-days-active-directory-sharepoint-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-zero-days-active-directory-sharepoint-exploited</guid><description>Microsoft addresses 622 vulnerabilities, including two actively exploited zero-days in Active Directory and SharePoint Server.</description><pubDate>Wed, 15 Jul 2026 02:35:14 GMT</pubDate><category>Microsoft</category><category>Active Directory</category><category>SharePoint Server</category><category>Zero-Day</category><category>Patch Tuesday</category><category>Vulnerability</category></item><item><title>AI-Built Ransomware Toolkit Automates EDR Evasion, AD Discovery</title><link>https://runtimerebel.com/blog/ai-built-ransomware-toolkit-automates-edr-evasion-ad-discovery</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-built-ransomware-toolkit-automates-edr-evasion-ad-discovery</guid><description>New AI-powered ransomware toolkit automates Active Directory discovery and EDR evasion, posing advanced threats. Learn its capabilities and mitigation strategies.</description><pubDate>Tue, 02 Jun 2026 21:09:58 GMT</pubDate><category>Ransomware</category><category>AI</category><category>EDR Evasion</category><category>Active Directory</category><category>Toolkit</category><category>Threat Intelligence</category></item><item><title>CVE-2020-1472: How Attackers Exploit Windows Netlogon RCE — Patch Now</title><link>https://runtimerebel.com/blog/cve-2020-1472-how-attackers-exploit-windows-netlogon-rce-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2020-1472-how-attackers-exploit-windows-netlogon-rce-patch-now</guid><description>Threat actors are actively exploiting Zerologon (CVE-2020-1472), a critical Windows Netlogon RCE vulnerability that allows for full domain takeover.</description><pubDate>Mon, 01 Jun 2026 14:14:13 GMT</pubDate><category>CVE-2020-1472</category><category>Zerologon</category><category>Microsoft</category><category>Active Directory</category><category>Domain Controller</category></item><item><title>Optimizing Active Directory Security with Modern Password Policies</title><link>https://runtimerebel.com/blog/optimizing-active-directory-security-with-modern-password-policies</link><guid isPermaLink="true">https://runtimerebel.com/blog/optimizing-active-directory-security-with-modern-password-policies</guid><description>Learn how to implement NIST-compliant Active Directory password policies using passphrases and breached password protection to reduce identity-based risks.</description><pubDate>Wed, 27 May 2026 17:12:24 GMT</pubDate><category>Active Directory</category><category>Password Security</category><category>Nist Guidelines</category><category>Credential Protection</category></item><item><title>Windows Server 2016 DC Lookup Failures: KB5037763 Mitigation Guide</title><link>https://runtimerebel.com/blog/windows-server-2016-dc-lookup-failures-kb5037763-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-server-2016-dc-lookup-failures-kb5037763-mitigation-guide</guid><description>Microsoft confirms a regression in Windows Server 2016 causing LSASS crashes and domain controller lookup failures after the May 2024 security update.</description><pubDate>Tue, 26 May 2026 09:19:29 GMT</pubDate><category>Windows Server 2016</category><category>Lsass Crash</category><category>Kb5037763</category><category>Active Directory</category><category>Microsoft Patch</category></item><item><title>Active Directory Post-Breach Persistence: Why Password Resets Fail</title><link>https://runtimerebel.com/blog/active-directory-post-breach-persistence-why-password-resets-fail</link><guid isPermaLink="true">https://runtimerebel.com/blog/active-directory-post-breach-persistence-why-password-resets-fail</guid><description>Explaining why password resets fail to evict attackers from Active Directory due to Kerberos ticket persistence and MSV1_0 credential caching mechanisms.</description><pubDate>Mon, 11 May 2026 17:01:15 GMT</pubDate><category>Active Directory</category><category>Kerberos</category><category>Persistence</category><category>Krbtgt</category><category>Incident Response</category></item><item><title>Microsoft Releases OOB Updates to Fix Windows Server Boot Issues</title><link>https://runtimerebel.com/blog/microsoft-releases-oob-updates-to-fix-windows-server-boot-issues</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-releases-oob-updates-to-fix-windows-server-boot-issues</guid><description>Microsoft issues emergency out-of-band updates to resolve critical authentication failures and boot loops caused by the April 2026 security patches.</description><pubDate>Mon, 20 Apr 2026 08:53:35 GMT</pubDate><category>Windows Server</category><category>Out of Band Update</category><category>Active Directory</category><category>Patch Management</category><category>Authentication</category></item><item><title>Windows Server Domain Controllers Hit by LSASS Reboot Loops</title><link>https://runtimerebel.com/blog/windows-server-domain-controllers-hit-by-lsass-reboot-loops</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-server-domain-controllers-hit-by-lsass-reboot-loops</guid><description>Microsoft confirms LSASS crashes causing persistent reboot loops on Windows Server Domain Controllers following the April 2024 security update cycle.</description><pubDate>Fri, 17 Apr 2026 08:42:20 GMT</pubDate><category>Windows Server</category><category>Lsass</category><category>Kb5036909</category><category>Domain Controller</category><category>Active Directory</category></item><item><title>Proactive Defense: Hardening Against Destructive Cyberattacks (2026 Edition)</title><link>https://runtimerebel.com/blog/proactive-defense-hardening-against-destructive-cyberattacks-2026-edition</link><guid isPermaLink="true">https://runtimerebel.com/blog/proactive-defense-hardening-against-destructive-cyberattacks-2026-edition</guid><description>Comprehensive guide on hardening against destructive cyberattacks, including wipers, ransomware, and data destruction tactics across on-premises and cloud environments.</description><pubDate>Fri, 06 Mar 2026 16:26:03 GMT</pubDate><category>Destructive Attacks</category><category>Wiper Malware</category><category>Ransomware</category><category>Hardening</category><category>Cyber Resilience</category><category>MFA</category><category>Backup</category><category>Active Directory</category><category>Kubernetes</category><category>CI CD</category><category>Cloud Security</category><category>Network Segmentation</category></item></channel></rss>