216.73.216.197

Stolen Service Accounts Lead to Rogue Workstations and Deep AD Compromise

· Published 11/03/2026 11:10 · Modified 16/03/2026 09:51

Export JSON

Essential information

Published
11/03/2026 11:10
Modified
16/03/2026 09:51
Tags
2026-03-11 CVE-2025-59718 CVE-2025-59719 CVE-2026-24858 credential-theft fortigate lateral movement ngfw rmm tools
Related entities
3 vulnerabilities (cve), 2 observables, 12 techniques (mitre), 2 others

Description

SentinelOne's DFIR team has responded to multiple incidents involving compromised appliances used to establish footholds in targeted environments. Attackers exploited vulnerabilities or weak credentials to access devices, extract configuration files containing service account credentials, and use those to join rogue workstations to Active Directory. In one case, the attacker used the access to deploy remote management tools and steal the NTDS.dit file. The incidents highlight the need for strong access controls, patching, and improved logging on edge devices. Organizations are advised to implement SIEM solutions to detect anomalous activity and automate responses.

External references