logo

Why Changing Passwords Doesn’t End an Active Directory Breach

ID: 5ea55f62-d5e1-58f3-9cfb-a4649a168a00

STIX ID: report--5ea55f62-d5e1-58f3-9cfb-a4649a168a00

Feed Name: Bleeping Computer

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Sponsored by Specops Software

...
...

This vendor-written advisory explains that password resets in on-premises Active Directory and hybrid Entra ID environments can leave short windows where old credentials or Kerberos tickets remain valid, enabling attackers to persist via cached hashes, active sessions, forged tickets (Golden/Silver), service account compromise, or ACL manipulation; it recommends actions such as forcing logoffs/reboots, purging Kerberos tickets, resetting the KRBTGT account, rotating service account credentials, and auditing ACLs and privileged roles to fully evict attackers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.