
Yuval Gordon
@YuG0rd
Followers
1K
Following
456
Media
3
Statuses
80
Security Researcher at Akamai. Opinions are my own.
Joined December 2017
🚀 We just released my research on BadSuccessor - a new unpatched Active Directory privilege escalation vulnerability.It allows compromising any user in AD, it works with the default config, and. Microsoft currently won't fix it 🤷♂️.Read Here -
22
373
867
RT @cybersaiyanIT: Another Monday. Another week of… endless emails, annoying meetings, and oh look, a three-headed monkey behind you!. Now….
0
9
0
RT @akamai_research: If you can't beat them, ban them 😏 . Malicious Cryptominers can be tough to dismantle - but we found a way. 👀 By explo….
0
7
0
RT @yo_yo_yo_jbo: פיד ישראל: מקומות שניתן לתרום להם בדולרים ויש להם חשבון ב benevity?.🇮🇱 אשמח אם תעזרו לי להפיץ את ההודעה.
0
4
0
The relevant section on our blog:
akamai.com
Akamai researchers found a privilege escalation vulnerability in Windows Server 2025 that allows attackers to compromise any user in Active Directory.
0
6
35
Many missed this on #BadSuccessor: it’s also a credential dumper. I wrote a simple PowerShell script that uses Rubeus to dump Kerberos keys and NTLM hashes for every principal-krbtgt, users, machines. no DCSync required, no code execution on DC.
9
154
499
RT @_logangoins: I'm super happy to announce an operationally weaponized version of @YuG0rd's BadSuccessor in .NET format! With a minimum o….
github.com
SharpSuccessor is a .NET Proof of Concept (POC) for fully weaponizing Yuval Gordon’s (@YuG0rd) BadSuccessor attack from Akamai. - logangoins/SharpSuccessor
0
170
0
RT @JoeDibley2: We just released a new beta build for PingCastle on GitHub to detect the new BadSuccessor risk that @YuG0rd found!. https:/….
github.com
This is a beta release that adds a new risk for BadSuccessor where delegations are detected on OUs that may allow abuse Update: Added a fix where some ACLs were being incorrectly detected. EG: Full...
0
9
0
RT @jaredcatkinson: We did an analysis across participating customers & found that ~96% had > 1 user that has the necessary permissions to….
0
8
0
RT @akamai_research: Today we unveil BadSuccessor - a new no-fix Active Directory privilege escalation technique. We will explore the rece….
0
182
0