A security incident disclosed that hackers exploited over 3,000 publicly available ASP.NET machine keys to execute remote code on IIS servers using ViewState code injection. This breach underscores developers’ vulnerabilities in managing machine keys, critical for web application security. Microsoft advises regular key rotation, enhanced monitoring, and using security tools to mitigate these risks and detect potential attacks.
![](https://healsecurity.com/wp-content/uploads/2025/02/new-attack-abusing-kerberos-delegation-in-active-directory-networks.webp.jpeg)
New Attack Abusing Kerberos Delegation in Active Directory Networks
A new attack vector exploiting vulnerabilities in Unconstrained Kerberos Delegation within Active Directory poses serious enterprise security risks. Attackers can create a “Ghost Server,” impersonate