
Access Broker Steals Kerberos Secrets to Gain Permanent Control of Enterprise Domains
An exposed server linked to a Russia-nexus threat actor has revealed a large-scale initial access operation targeting organizations worldwide. The activity shows how one operator exploited internet-facing appliances, stole credentials, moved through Windows networks, and gained complete control of Active Directory domains. The recovered directory contains a command-level record of activity from mid-2025 through late […]
The post Access Broker Steals Kerberos Secrets to Gain Permanent Control of Enterprise Domains appeared first on Cyber Security News.