Why Changing Passwords Doesn’t End an Active Directory Breach
ID: 5ea55f62-d5e1-58f3-9cfb-a4649a168a00
STIX ID: report--5ea55f62-d5e1-58f3-9cfb-a4649a168a00
Feed Name: Bleeping Computer
This vendor-written advisory explains that password resets in on-premises Active Directory and hybrid Entra ID environments can leave short windows where old credentials or Kerberos tickets remain valid, enabling attackers to persist via cached hashes, active sessions, forged tickets (Golden/Silver), service account compromise, or ACL manipulation; it recommends actions such as forcing logoffs/reboots, purging Kerberos tickets, resetting the KRBTGT account, rotating service account credentials, and auditing ACLs and privileged roles to fully evict attackers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
