Tag: vulnerability

Week 31 – CertiGhost: The Certificate That Shouldn’t Exist

27 July – 02 Aug 2026 This week’s CVE of the Week is CVE-2026-54121, also known as CertiGhost, a critical vulnerability affecting Microsoft Active Directory Certificate Services (AD CS). The flaw allows a low-privileged authenticated domain user to obtain a certificate for a Domain Controller, 

Faking GitHub Commits – What Could Go Wrong?

Faking GitHub Commits – What Could Go Wrong?

Found: a tool creating dummy GitHub source code commits to help programmers game job evaluation mechanisms. This illustrates a deeper issue with how badly designed incentives can have serious security consequences.

Article Publication – “Protecting Responsible Cybersecurity Vulnerability Research”

CyAN members John Salomon and Nick Kelly have just published an article in the European Cybersecurity Journal on the legal treatment of responsible cybersecurity vulnerability disclosure.