Wednesday, 11 June 2025
31.1 C
Singapore
33.5 C
Thailand
25.3 C
Indonesia
29.6 C
Philippines

Semperis and Akamai address critical Active Directory flaw in Windows Server 2025

Semperis and Akamai introduce new detection tools to counter a critical Windows Server 2025 vulnerability affecting Active Directory security.

Semperis has announced new detection features in its Directory Services Protector (DSP) platform to guard against a critical security flaw in Windows Server 2025. The vulnerability, known as “BadSuccessor,” allows attackers to escalate privileges by exploiting a new feature called delegated Managed Service Accounts (dMSAs).

The update was developed in collaboration with Akamai, whose research team first uncovered the flaw. With no official patch currently available, these new capabilities offer a practical way for organisations to monitor and detect suspicious activity before a compromise can take place.

Exposing a flaw in service account delegation

The BadSuccessor vulnerability targets dMSAs, a feature introduced in Windows Server 2025 intended to strengthen service account security. However, Akamai researchers discovered that attackers can exploit dMSAs to impersonate high-privilege Active Directory users, including Domain Admins. This can be done without triggering alerts and without requiring an available patch.

The flaw highlights a broader issue in enterprise identity security: poor governance of service accounts. These accounts are often configured with excessive privileges or left unmonitored, giving attackers a hidden path to escalate access and move laterally across networks.

“The abuse of service accounts is a growing concern, and this high-profile vulnerability is a wake-up call,” said Yuval Gordon, Security Researcher at Akamai. “Semperis moved quickly to translate the vulnerability into real-world detection capabilities for defenders, demonstrating how collaboration between researchers and vendors can lead to rapid, meaningful impact.”

New detection features added to Semperis DSP

In response to the vulnerability, Semperis has introduced one new Indicator of Exposure (IOE) and three Indicators of Compromise (IOCs) to its DSP platform. These updates are designed to help security teams identify abnormal behaviour linked to dMSAs.

The indicators focus on detecting excessive delegation rights, suspicious associations between dMSAs and privileged accounts, and attempts to manipulate sensitive accounts such as KRBTGT, which handles authentication tickets in Active Directory.

Tomer Nahum, Security Researcher at Semperis, said, “Service accounts remain one of the least governed yet most powerful assets in enterprise environments. This collaboration with Akamai allowed us to close detection gaps fast and give defenders visibility into a deeply complex area of Active Directory that attackers continue to exploit.”

Call for proactive defence until a patch is available

The vulnerability affects any organisation running at least one domain controller on Windows Server 2025. Even a single misconfigured server could expose the entire environment to risk. While Microsoft has not yet issued a fix, Semperis and Akamai are urging organisations to take immediate action.

Until a patch is released, businesses are advised to audit their dMSA configurations and use updated detection platforms such as Semperis DSP to monitor for signs of misuse. The swift collaboration between security vendors and researchers is seen as a positive step in addressing identity-based threats before they cause widespread damage.

Hot this week

Xiaomi launches new Robot Vacuum S40C with better suction and smarter navigation

Xiaomi’s new Robot Vacuum S40C brings better suction and smart navigation at a lower price, now available for just S$189.

New Relic report shows ChatGPT leads as developers expand AI model use

New Relic’s 2025 AI Impact Report shows ChatGPT leads in usage, while model diversity and AI monitoring adoption continue to grow.

Gemini now lets you schedule AI tasks — here’s how it works

Google’s Gemini app now includes Scheduled Actions, letting users automate AI tasks and reminders within the Google ecosystem.

Hybrid working emerges as key strategy for business resilience and cost control

New survey finds hybrid working helps CEOs cut costs and build business resilience amid economic uncertainty.

Apple delays launch of smarter Siri, leaving AI fans waiting

Apple will delay AI-powered Siri until 2026 as WWDC 25 skips the update and focuses instead on other AI features and improvements.

Nothing to launch new over-ear headphones and flagship smartphone on 2 July

Nothing will unveil its first over-ear headphones and flagship smartphone, Phone (3), in a global launch event on 2 July.

Singapore Airlines and PALO IT test generative AI for faster software development

Singapore Airlines and PALO IT successfully trial Gen-e2, an AI-first software development approach powered by GitHub Copilot.

AI helps uncover gender-specific drug combinations to improve heart valve disease treatment

Researchers use AI to find gender-specific drug combinations for AVS, aiming to improve personalised treatment for heart valve disease.

OpenAI delays the release of new open model until later this summer

OpenAI delayed its new open AI model, now expected later this summer, aiming to rival Mistral and Qwen.

Related Articles

Popular Categories