Category

identity-security

21 articles

Kerberoasting: How Attackers Crack AD Service Accounts

Background Kerberoasting is an attack technique that leverages the Kerberos authentication protocol used by Microsoft Active Directory to extract password hashes from service accounts and crack them offline. The method relies on the presence of Service Principal Names (SPNs) associated with user or computer accounts in AD. When a client

Edgerunner Edgerunner 8 min read
identity-security identity-security phishing opinion

MFA Fatigue Is Real — And It's Getting Worse

The Real Problem Because of course, security was brought in two weeks before go‑live. MFA fatigue isn’t a new threat—it’s the same old “click‑through” attack wrapped in a more convincing social‑engineering story. The real problem is that modern identity platforms treat MFA prompts as

Edgerunner Edgerunner 3 min read

CVE-2026-42826 Azure DevOps Sensitive Data Exposure: Hardening Pipelines to Stop Unauthorized Disclosure

Background The year 2026 continues to underscore a painful lesson: security is not an afterthought—it’s the foundation of any resilient operation. The recent spate of critical vulnerabilities in Microsoft Azure and GitHub Enterprise Server isn’t just a collection of isolated bugs; it reflects a broader pattern where

Edgerunner Edgerunner 4 min read

Why Security Awareness Training Fails (and What to Do Instead)

The Real Problem Because security awareness programs are often treated like a checkbox exercise rather than an integral part of operational workflows, they inevitably fail to meaningfully reduce risk. When training sessions become disconnected from real‑world scenarios and daily tools, the knowledge gained evaporates as soon as employees return

Edgerunner Edgerunner 2 min read

Eliminate Wildcard IAM Permissions: Hardening AWS Roles Before They Leak

Background In today’s cloud-first world, AWS IAM roles are often created in a rush to meet business deadlines or to support new applications. The result is a proliferation of overly permissive policies—wildcard actions, broad resource patterns, and blanket “admin” privileges that make the security posture fragile at best.

Edgerunner Edgerunner 4 min read
identity-security identity-security cve zero-trust

Hardening Intune Conditional Access to Block CVE‑2026‑6973 Admin Abuse

Background The threat landscape has shifted dramatically in 2026, with attackers increasingly leveraging high-severity vulnerabilities to achieve initial footholds and later-stage privilege escalation. The addition of CVE-2026-42208 (BerriAI LiteLLM SQL Injection) and CVE-2026-0300 (PAN-OS out-of-bounds write) to the CISA Known Exploited Vulnerabilities registry signals that even seemingly niche software can

Edgerunner Edgerunner 5 min read