Kerberos Relay Attack is a mitre_attack tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.
Kerberos Relay Attack is a mitre_attack tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed January 19, 2026; most recent activity January 19, 2026.
A new vulnerability in Windows Kerberos authentication allows attackers to exploit DNS CNAME responses to bypass existing defenses in Active Directory environments. This flaw significantly increases the attack surface…
Kerberos Relay Attack is a mitre_attack tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.
The most recent intelligence report mentioning Kerberos Relay Attack on ThreatCluster is dated January 19, 2026.
Across ThreatCluster reporting, Kerberos Relay Attack most frequently co-occurs with Credential Relay Attack, Windows.
The most significant recent cluster is “Kerberos Relay Attack Exploits DNS CNAME Responses” (2 articles · Updated January 19, 2026). Kerberos Relay Attack appears across 1 threat cluster in total, listed above with sources.
Kerberos Relay Attack appears in 1 intelligence report mention across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.