Microsoft Active Directory — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
November 12, 2025
Last Seen
May 19, 2026

Microsoft Active Directory is a technology platform tracked across 6 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed November 12, 2025; most recent activity May 19, 2026.

Overview

Microsoft Active Directory is a centralized directory service that provides authentication, authorization, and policy-based access control across Windows domains. It serves as a foundational identity and access management platform in many enterprises, and its compromise can enable privilege escalation, lateral movement, and credential theft, making it a critical focus for defenders and attackers alike.

Related Threat Clusters

Recent Intelligence Reports

  • Patch bypass allows hackers to exploit prior flaw in SonicWall SSL — Cybersecuritydive · May 19, 2026
  • BloodHound expands identity attack path mapping reach — Itbrief.Co.Nz · March 19, 2026
  • Microsoft Active Directory Flaw Allows Attackers to Escalate Privileges — Gbhackers · March 11, 2026
  • SpecterOps Intros BloodHound Scentry to Help Enterprises, MSSPs Build Identity APM Programs — Msspalert · February 10, 2026
  • Commvault enhances identity resilience with new Active Directory tools — Securitybrief.Au · November 12, 2025

CVSS v3.1 Breakdown