Friday, 19 December 2025
27.4 C
Singapore
29.2 C
Thailand
27.3 C
Indonesia
27.5 C
Philippines

Semperis and Akamai address critical Active Directory flaw in Windows Server 2025

Semperis and Akamai introduce new detection tools to counter a critical Windows Server 2025 vulnerability affecting Active Directory security.

Semperis has announced new detection features in its Directory Services Protector (DSP) platform to guard against a critical security flaw in Windows Server 2025. The vulnerability, known as “BadSuccessor,” allows attackers to escalate privileges by exploiting a new feature called delegated Managed Service Accounts (dMSAs).

The update was developed in collaboration with Akamai, whose research team first uncovered the flaw. With no official patch currently available, these new capabilities offer a practical way for organisations to monitor and detect suspicious activity before a compromise can take place.

Exposing a flaw in service account delegation

The BadSuccessor vulnerability targets dMSAs, a feature introduced in Windows Server 2025 intended to strengthen service account security. However, Akamai researchers discovered that attackers can exploit dMSAs to impersonate high-privilege Active Directory users, including Domain Admins. This can be done without triggering alerts and without requiring an available patch.

The flaw highlights a broader issue in enterprise identity security: poor governance of service accounts. These accounts are often configured with excessive privileges or left unmonitored, giving attackers a hidden path to escalate access and move laterally across networks.

“The abuse of service accounts is a growing concern, and this high-profile vulnerability is a wake-up call,” said Yuval Gordon, Security Researcher at Akamai. “Semperis moved quickly to translate the vulnerability into real-world detection capabilities for defenders, demonstrating how collaboration between researchers and vendors can lead to rapid, meaningful impact.”

New detection features added to Semperis DSP

In response to the vulnerability, Semperis has introduced one new Indicator of Exposure (IOE) and three Indicators of Compromise (IOCs) to its DSP platform. These updates are designed to help security teams identify abnormal behaviour linked to dMSAs.

The indicators focus on detecting excessive delegation rights, suspicious associations between dMSAs and privileged accounts, and attempts to manipulate sensitive accounts such as KRBTGT, which handles authentication tickets in Active Directory.

Tomer Nahum, Security Researcher at Semperis, said, “Service accounts remain one of the least governed yet most powerful assets in enterprise environments. This collaboration with Akamai allowed us to close detection gaps fast and give defenders visibility into a deeply complex area of Active Directory that attackers continue to exploit.”

Call for proactive defence until a patch is available

The vulnerability affects any organisation running at least one domain controller on Windows Server 2025. Even a single misconfigured server could expose the entire environment to risk. While Microsoft has not yet issued a fix, Semperis and Akamai are urging organisations to take immediate action.

Until a patch is released, businesses are advised to audit their dMSA configurations and use updated detection platforms such as Semperis DSP to monitor for signs of misuse. The swift collaboration between security vendors and researchers is seen as a positive step in addressing identity-based threats before they cause widespread damage.

Hot this week

Sony brings affordable full-body motion capture to aspiring VTubers in Singapore

Sony launches its Mocopi motion capture system in Singapore, offering VTubers an affordable, smartphone-based way to capture full-body movement.

Antler invests US$5.6 million across 14 AI startups with early commercial traction

Antler invests US$5.6 million in 14 AI startups with early traction, focusing on applied AI and real-world enterprise adoption.

Plaud Note Pro launches in Singapore as AI-powered note-taking device

Plaud launches the Note Pro in Singapore, introducing a slim AI note-taker with real-time human-AI alignment and up to 50 hours of recording.

Deel becomes Arsenal’s official HR platform partner in multi-year global deal

Deel signs a multi-year global partnership with Arsenal, becoming the club’s Official HR Platform Partner and supporting its global operations.

Tiiny AI unveils pocket-sized AI supercomputer verified by Guinness World Records

Tiiny AI reveals a Guinness-verified pocket-sized AI supercomputer designed to run massive models locally without relying on the cloud.

The rise of agentic AI and what it means for enterprise leaders

Agentic AI is accelerating across Asia, pushing leaders to rethink productivity, governance, and the infrastructure needed for long-term competitiveness.

Apple explores iPhone-class chip for future MacBook, leaks suggest

Leaked Apple files hint at testing a MacBook powered by an iPhone-class chip, suggesting a possible lower-cost laptop in the future.

Delta Electronics Singapore signs MOU with NUS to advance sustainable data centre innovation

Delta Electronics Singapore and NUS partner to develop sustainable, AI-ready data centre technologies for tropical environments.

Zoom introduces AI Companion 3.0 with a web-based assistant and expanded task automation

Zoom launches AI Companion 3.0, adding a web-based assistant that automates tasks, drafts emails and reshapes the platform into an AI workspace.

Related Articles

Popular Categories