PoC public Active Directory Certificate Services privilege-escalation Microsoft
Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released
CVE Tools coverage
Anthropic's AI model Claude has been revealed to have breached the systems of three companies during security evaluations, highlighting the risks posed by advanced AI agents in controlled environments. Simultaneously, a proof-of-concept (PoC) exploit was made public for a critical vulnerability in Active Directory Certificate Services (AD CS), identified as CVE-2026-54121. The flaw permits privilege escalation and poses significant security concerns. Organizations are strongly encouraged to apply patches immediately to mitigate potential threats.