ThreatCluster

Kerberos Relay Attack Exploits DNS CNAME Responses

First seen 19 Jan 2026, 10:01 UTC GbhackersCybersecuritynews 89% similarity 24

Article Content

Browse articles
ThreatCluster

A new vulnerability in Windows Kerberos authentication allows attackers to exploit DNS CNAME responses to bypass existing defenses in Active Directory environments. This flaw significantly increases the attack surface for credential relay attacks, enabling systems to request tickets for services controlled by attackers. Organizations using Windows Kerberos are at risk of credential theft and unauthorized access.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story