CISA and five international cybersecurity agencies published technical guidance documenting 17 techniques hackers use to compromise Microsoft Active Directory environments, exploiting identity configurations, legacy protocols, and certificate services to escalate privileges and establish persistence in enterprise networks.
Microsoft's Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. The issue appears linked to the Windows Machine Identity Isolation security feature being set to enforcement mode after the update, causing machines to lose their secure channel with Active Directory. Administrators can restore access by disabling the feature and repairing the secure channel using PowerShell.