Microsoft patched CVE-2026-69730, a CVSS 9.8 remote code execution flaw in the Windows DNS Server role reachable with one unauthenticated packet to port 53. In most Active Directory shops that role runs on the domain controller, so the box answering on port 53 also holds the identity database.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence40
Symantec says Warlock operators ran an AV/EDR killer across at least 40 machines in roughly two hours after a suspected SharePoint compromise. The ransomware payloads moved between domain controllers through SYSVOL replication.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence55
Detection at the first hop forced CISA's red team onto donated access at Organization B. It did not stop the team reaching the same sensitive systems it reached at Organization A.
Perspective Coverage
5 publishers
- Builder
- Builder 39%
- Operator
- Operator 53%
- Investor
- Investor 8%
Reality
- Evidence76
- Adoption
- Insufficient
- Hype gap+12
- Incentives35
- Confidence72
GreyNoise and Blackpoint Cyber trace the new PaperCut auth-bypass chain to one scanning address running AI agents against schools, which turns an unpatched print server from a maintenance ticket into a credential incident.
Perspective Coverage
6 publishers
- Builder
- Builder 31%
- Operator
- Operator 57%
- Investor
- Investor 12%
Reality
- Evidence62
- Adoption38
- Hype gap+20
- Incentives40
- Confidence66
Kaspersky's responders found no encrypted files and no malware on disk across the Windows estate of a Middle East manufacturer in April 2026. The impact arrived through one Group Policy Object linked at the domain root.
Reality
- Evidence62
- Adoption35
- Hype gap+12
- Incentives72
- Confidence58
Australia's ASD ACSC wrote the guidance with CISA, the NSA, Canada's CCCS and the British and New Zealand cyber centres, pairing the 17 most common Active Directory compromise techniques with mitigations.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+12
- Incentives40
- Confidence66
Huntress's second post on Active Directory Rights Management Service traces every protected document back to one private key. The certificate runs 255 years, the key has no expiry, and the product ships no way to rotate it.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+12
- Incentives60
- Confidence50
GreyNoise says a likely Russian-speaking actor built and tested PaperCut exploits in a lab, then ran hundreds of agents on a Codex harness with a DeepSeek model against 440 servers in 48 countries. The sending infrastructure was already on its watchlist.
Publishers:greynoise.io
Reality
- Evidence58
- Adoption70
- Hype gap+12
- Incentives68
- Confidence55
Six weeks of lab work on a role Microsoft no longer develops but still supports on Windows Server 2025 ended with an offline decrypt of a protected document and a private key stamped valid until 2258 that nobody can rotate.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+18
- Incentives60
- Confidence50
A public proof-of-concept for CVE-2026-54121 shows an Enterprise CA vouching for a forged Domain Controller identity. Microsoft's July 14 fix adds a missing check, not judgement.
Reality
- Evidence42
- Adoption22
- Hype gap+24
- Incentives78
- Confidence46