Back to news

Active Directory Exploit and Smart TV Proxy Abuse Raise Enterprise Security Flags

A new certificate-based AD attack grants domain-level access to low-privileged users, while LG moves to purge proxy-abusing apps from its smart TV platform.

Active Directory Exploit and Smart TV Proxy Abuse Raise Enterprise Security Flags

What happened

Security researchers H0j3n and Aniq Fakhrul released a working proof-of-concept exploit on July 24, dubbed Certighost, that allows any low-privileged Active Directory user to obtain a certificate impersonating a Domain Controller. Once authenticated as that machine, an attacker can invoke DCSync to extract the krbtgt account secret — effectively granting full control over the domain's Kerberos authentication infrastructure. Separately, LG Electronics USA announced plans to remove smart TV applications from its webOS store that silently enroll users' televisions as residential proxy nodes, routing third-party internet traffic through home networks without meaningful user consent. The action follows research showing that over 42 percent of apps in the store carried this behavior.

Why it matters for your business

Certighost is particularly dangerous because it requires no elevated starting position — a single compromised employee credential is sufficient to pivot to full domain compromise via DCSync, bypassing many conventional privilege escalation controls. Organizations running Active Directory Certificate Services should audit certificate templates immediately for misconfigurations that permit machine-account enrollment by unprivileged principals. The LG smart TV issue is a reminder that consumer-grade connected devices routinely end up on corporate and hybrid home-office networks, where they can become unwitting traffic relay points for malicious actors. Security teams should inventory IoT and entertainment devices on any network segment that touches corporate resources and apply strict egress filtering.

What to watch next

Microsoft has not yet issued formal guidance specific to the Certighost attack chain, so practitioners should monitor advisories from the Microsoft Security Response Center and evaluate whether Certifried-era mitigations fully address this variant. On the LG front, it remains unclear how the company will technically enforce the ban or audit apps already installed on millions of deployed televisions, making the effectiveness of the policy difficult to assess until enforcement details emerge.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp