Threat Brief — 2026-07-24 — Certighost, hotel DNS hijacks, Kratos takedown
Executive summary. A working exploit for "Certighost" lets any low-privileged Active Directory user impersonate a Domain Controller — the most urgent defensive item today. On the offensive side, attackers are hijacking hotel Wi-Fi DNS to redirect guests to fake M365 login pages, and BlueNoroff (DPRK) is operating a dedicated Zoom/Teams phishing kit that profiles crypto wallets before malware delivery. On the positive side, German and US law enforcement seized 200+ servers behind the Kratos M365 phishing platform and arrested its developer. Microsoft also confirmed that Thursday's massive M365/Azure outage was caused by an automated maintenance bug that over-pruned IP routes — a root-cause update to the story we first noted yesterday.
Top items
- Certighost exploit enables low-privileged AD users to impersonate Domain Controllers. Researchers H0j3n and Aniq Fakhrul published a working exploit (July 24) that allows any low-privileged AD user to obtain a certificate for a Domain DC and authenticate as that machine — effectively collapsing the privilege boundary. If you run AD Certificate Services, treat this as a high-priority review item: restrict certificate templates and audit ESC-style misconfigurations immediately. (src: The Hacker News)
- Hotel/conference Wi-Fi DNS hijack redirects users to fake M365 login pages. Attackers are modifying DNS settings on Wi-Fi infrastructure at hotels and conference centres to transparently redirect traffic to credential-harvesting Microsoft 365 portals. This is an active, opportunistic campaign — relevant for anyone supporting travelling staff or conference attendees. Advise users to verify URLs before entering credentials and to use VPN or cellular tethering on untrusted networks. (src: BleepingComputer)
- BlueNoroff (DPRK) Zoom/Teams phishing kit profiles crypto wallets before malware delivery. North Korean threat actors are operating a dedicated phishing kit behind typosquatted Zoom and Teams domains (ClickFix-style). The kit doesn't just harvest credentials — it profiles victims' crypto wallets before selectively deploying malware, indicating a targeted post-compromise workflow rather than mass spray-and-pray. (src: The Hacker News)
- Law enforcement seizes Kratos phishing platform (200+ servers) and arrests developer. German and US authorities shut down the Kratos platform, which was purpose-built for stealing M365 credentials and bypassing MFA. Over 200 servers were seized. This is a significant disruption of phishing-as-a-service infrastructure, though residual tooling and copycat kits will likely persist. (src: Xakep)
- Microsoft blames M365/Azure outage on automated maintenance bug — root cause confirmed. Microsoft identified that a bug in its automated network maintenance system mistakenly removed IP routes from more devices than intended, cascading into the Azure and M365 disruption reported Thursday. This is a genuine development in the outage story first reported 2026-07-23 by BleepingComputer. (src: BleepingComputer)
- Former DPRK state hackers arrested for breaching North Korea's Central Bank. North Korean security services arrested a group of former government hackers who compromised internal networks of the Central Bank and Foreign Trade Bank, exfiltrating funds via cryptocurrency and smuggling. Unusual insider threat dynamic — former offensive operators turning on their own state's financial infrastructure. (src: Xakep)
- Verus Ethereum bridge loses additional $7.5M via one-cent exploitation loophole. Researchers linked a new $7.5M theft on the Verus bridge to a May attack that netted $11.58M, suggesting the underlying vulnerability was not fully remediated after the first incident. This develops the cross-chain bridge attack story first reported 2026-07-24 by Xakep. (src: SecurityLab)
- Google Threat Intelligence Group rolls out unified threat-actor naming schema. GTIG is standardising its tracking taxonomy across platforms to replace the current proliferation of overlapping aliases. Low operational urgency but relevant for threat-intel teams reconciling actor names across vendor feeds. (src: Google Cloud Blog)
Themes
- M365 credential theft is the common thread. Three of today's top items — hotel DNS hijacks, BlueNoroff's Zoom kit, and the Kratos takedown — all centre on stealing Microsoft 365 identities. M365 remains the primary credential target across both opportunistic and state-aligned actors.
- Law enforcement momentum continues. The Kratos seizure (200+ servers, developer arrested) adds to recent enforcement wins, but the persistence of phishing kits and copycat infrastructure means the operational impact may be temporary.
- Bridge security deja vu. The Verus bridge's $7.5M repeat loss — linked to an unresolved May vulnerability — reinforces that cross-chain bridges remain systematically under-secured and that post-incident remediation in DeFi is often incomplete.
===
