Skip to content
ThreatCluster

Kerberos Relay Attack Exploits DNS CNAME Responses

First seen 19 Jan 2026, 10:01 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

A new vulnerability in Windows Kerberos authentication allows attackers to exploit DNS CNAME responses to bypass existing defenses in Active Directory environments. This flaw significantly increases the attack surface for credential relay attacks, enabling systems to request tickets for services controlled by attackers. Organizations using Windows Kerberos are at risk of credential theft and unauthorized access.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 193d ago How this analysis works

More articles in this cluster (2)