Microsoft Active Directory is a technology platform tracked across 6 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed November 12, 2025; most recent activity May 19, 2026.
Microsoft Active Directory is a centralized directory service that provides authentication, authorization, and policy-based access control across Windows domains. It serves as a foundational identity and access management platform in many enterprises, and its compromise can enable privilege escalation, lateral movement, and credential theft, making it a critical focus for defenders and attackers alike.
On March 10, 2026, Microsoft released a critical security update addressing a high-severity vulnerability in Active Directory Domain Services (AD DS), tracked as CVE-2026-25177. This flaw, with a CVSS score of 8.8,…
A wave of attacks exploiting CVE-2024-12802, an authentication bypass vulnerability in SonicWall SSL VPN appliances, began in February 2026. Despite a firmware patch issued in 2025, attackers were able to bypass…
SpecterOps has expanded its BloodHound Enterprise tool to include identity attack path mapping for Okta, GitHub, and Mac environments managed through Jamf. This update addresses the increasing number of intrusions that…
Commvault has introduced new enhancements to its Identity Resilience portfolio aimed at improving security for Microsoft Active Directory environments. These tools are designed to help organizations detect, audit, and…
SpecterOps has introduced BloodHound Scentry, a new service aimed at helping organizations improve their attack path management (APM) practices and reduce identity-related risks. This service integrates BloodHound…
Commvault has introduced enhancements to its Identity Resilience portfolio aimed at improving security for Microsoft Active Directory environments. The new capabilities focus on detecting, auditing, and reversing…