#Badsuccessor
BadSuccessor is a new AD attack primitive that abuses dMSAs, allowing an attacker who can modify or create a dMSA to escalate privileges and take over the forest.

Check out @jimsycurity.adminsdholder.com's latest blog post to understand how you can mitigate risk. ghst.ly/4kXTLd9
Understanding & Mitigating BadSuccessor - SpecterOps
Understanding the impact of the BadSuccessor AD attack primitive and mitigating the abuse via targeted Deny ACEs on Organizational Units.
ghst.ly
May 27, 2025 at 9:11 PM
#Akamai’s security team kicked off a new spat in the vulnerability disclosure world by publishing full exploitation details for “BadSuccessor,” an unpatched privilege
#CyberSecurity #InfoSec
www.securityweek.com/akamai-micro...
Akamai, Microsoft Disagree on Severity of Unpatched ‘BadSuccessor’ Flaw
Akamai documents a privilege escalation flaw in Windows Server 2025 after Redmond declines to ship an immediate patch.
www.securityweek.com
May 22, 2025 at 8:47 PM
🚨 BadSuccessor = Bad OPSEC

With the right audit config, it's pretty easy to detect BadSuccessor.

academy.bluraven.io/blog/detecti...

#ThreatHunting #DetectionEngineering #ThreatDetection
#BadSuccessor
Detecting BadSuccessor: Shorcut to Domain Admin
Detect BadSuccessor attacks exploiting dMSA in Windows Server 2025. Learn key detection methods and auditing configurations.
academy.bluraven.io
June 3, 2025 at 2:50 PM
Patching one technique doesn't close the entire attack vector.

dMSA abuse is still a problem, and @logangoins.bsky.social
just dropped a reality check with new tooling to prove it.

Learn more about the issue & the new BadTakeover BOF. ghst.ly/42POg9L
The (Near) Return of the King: Account Takeover Using the BadSuccessor Technique - SpecterOps
After Microsoft patched Yuval Gordon’s BadSuccessor privilege escalation technique, BadSuccessor returned with another blog from Yuval, briefly mentioning to the community that attackers can still abu...
ghst.ly
October 20, 2025 at 4:54 PM
This week's show is up on YouTube www.youtube.com/watch?v=auip...
May 23, 2025 at 11:28 PM
Happy #BloodHoundBasics Day!

This week's 🔥 topic from @martinsohn.dk: the Microsoft-wont-fix-yet "BadSuccessor" attack that abuses Server 2025's dMSA feature for domain takeover.

This 🧵 shows how you can use BloodHound to find BadSuccessor risk.

(1/9)
May 23, 2025 at 6:11 PM
If you haven’t read the BadSuccessor blog post, woo boy: www.akamai.com/blog/securit...
www.akamai.com
May 24, 2025 at 2:40 AM
BadSuccessor (@YuG0rd), o3 finds SMB 0day (@seanhn), crashing defender (@InfoGuard_Labs), MDT looting (@Oddvarmoe), and more!

blog.badsectorlabs.com/last-week-in...
Last Week in Security (LWiS) - 2025-05-27
BadSuccessor (@YuG0rd), o3 finds SMB 0day (@seanhn), crashing defender (@InfoGuard_Labs), MDT looting (@Oddvarmoe), and more!
blog.badsectorlabs.com
May 27, 2025 at 11:27 PM
BadSuccessor: Unpatched Microsoft Active Directory attack enables domain takeover
BadSuccessor: Unpatched Microsoft Active Directory attack enables domain takeover
Unprivileged users with permission to create objects inside an Active Directory organizational unit can abuse the new Delegated Managed Service Accounts (dMSA) feature to elevate their privilege to…
buff.ly
May 23, 2025 at 3:42 AM
-New SharePoint Restricted View bypass
-Unpatched BadSuccessor vulnerability in Windows
-Major Versa Concerto bugs unpatched
-GitLab Duo prompt injection attack
-Huge backlash against GitHub's Copilot integration
-CVSSv4 adoption remains low
-Botconf 2025 videos
May 23, 2025 at 7:49 AM
BadSuccessor (CVE-2025-53779) Technique Persists Despite Microsoft Patch
BadSuccessor (CVE-2025-53779) Technique Persists Despite Microsoft Patch
A new Active Directory flaw, BadSuccessor, allows low-privileged users to become Domain Admins. Akamai researchers warn that the technique remains a threat even after patching.
securityonline.info
August 31, 2025 at 4:51 AM
🚨 New on The Weekly Purple Team:
We deep dive BadSuccessor
See how the attack works + how to detect it in the real world.
🎥 youtu.be/IWP-8IMzQU8
🔍 Based on research by @Akamai
#PurpleTeam #BadSuccessor #ActiveDirectory #RedTeam #BlueTeam #CyberSecurity #DetectionEngineering
🛡️ Deep Dive: BadSuccessor – Full Active Directory Compromise
YouTube video by The Weekly Purple Team
youtu.be
June 4, 2025 at 12:56 PM
BadSuccessor: Abusing dMSA to Escalate Privileges in Active Directory
www.akamai.com
May 21, 2025 at 4:13 PM
BadSuccessor: Abusing dMSA to Escalate Privileges in Active Directory
www.akamai.com/blog/securit...
www.akamai.com
May 22, 2025 at 11:08 AM
⚠️ Note: BloodHound doesn't currently have all elements required for a full BadSuccessor audit, namely 'Create msDS-DelegatedManagedServiceAccount', 'Create all child objects', & dMSA nodes. For that, you should run Get-BadSuccessorOUPermissions.ps1 shared in Yuval's blog.

(8/9)
May 23, 2025 at 6:11 PM
-FreePBX zero-day
-BadSuccessor bug can still be exploited
-Cisco security updates
-CrowdStrike buys Onum
-New MystRodX backdoor
-Backdoor found in the AppSuite PDF Editor
-Reports on Qilin, Sinobi, and the BQTLOCK ransomware
-FIFA WC26 scam campaigns starting a year in advance
August 29, 2025 at 8:12 AM
Exploiting Delegated Managed Service Accounts (dMSAs) in Active Directory. BadSuccessor is a critical attack vector that emerged with the release of Windows Server 2025. Under certain conditions, users can leverage dMSAs to elevate privileges.
unit42.paloaltonetworks.com/badsuccessor...
When Good Accounts Go Bad: Exploiting Delegated Managed Service Accounts in Active Directory
BadSuccessor is an attack vector in Windows Server 2025. Under certain conditions it allows privilege elevation via dMSAs. We analyze its mechanics.
unit42.paloaltonetworks.com
August 6, 2025 at 3:48 PM
Just dropped my BadSuccessor .NET PoC showing how to abuse Delegated MSAs for AD access:

✔️ OU discovery
✔️ Zero-creds MSA creation
✔️ Works with user or machine account

Details + code:
🔗 github.com/ibaiC/BadSuc...
🧵 kreep.in/badsuccessor...
May 26, 2025 at 10:01 AM
Akamai vs. Microsoft: The “BadSuccessor” Smackdown Over Windows Server 2025 Flaw!

Akamai reveals "BadSuccessor" flaw in Windows Server 2025, sparking debate. Microsoft labels it "moderate," but Akamai disagrees. Who knew security could be this spicy?
thenimblenerd.com?p=1046386
Akamai vs. Microsoft: The “BadSuccessor” Smackdown Over Windows Server 2025 Flaw!
Akamai's security team ignited controversy by revealing details of the "BadSuccessor" flaw in Windows Server 2025. Microsoft labeled it as "moderate," but Akamai strongly disagrees, arguing it's a high-impact risk. The debate over responsible disclosure continues, as Akamai offers guidance in the absence of a patch.
thenimblenerd.com
May 22, 2025 at 5:14 PM
Exploiting BadSuccessor from A to Z with NT hash of impersonated accounts using bloodyAD v2.1.16
github.com/CravateRouge...
May 27, 2025 at 9:54 AM
When Good Accounts Go Bad: Exploiting Delegated Managed Service Accounts in
Active Directory
unit42.paloaltonetworks.com/badsuccessor...
When Good Accounts Go Bad: Exploiting Delegated Managed Service Accounts in Active Directory
BadSuccessor is an attack vector in Windows Server 2025. Under certain conditions it allows privilege elevation via dMSAs. We analyze its mechanics.
unit42.paloaltonetworks.com
August 7, 2025 at 11:34 AM