Ncerio News blogCVE feed
What we measure across the estates we audit

28 Active Directory Gaps Found in Estate Audit Amid Ransomware AI News

A GBHackers report details Aurora ransomware using AI to compromise 20+ orgs. Ncerio’s active-directory audit reveals 28 open findings across 1 target.
27 August 2026

Security publication GBHackers has reported on a Russian-speaking affiliate of the Aurora ransomware operation that compromised more than 20 organizations across nine countries. The incidents occurred between April and July 2026, marking a significant escalation in operational tactics within the threat landscape.

The group utilized the AI coding assistant Cursor to plan intrusion activity and facilitate Active Directory escalation. An exposed server provided an unusually complete view of the affiliate’s operational workflow. This artifact contained victim-specific directories, shell history, and other artifacts that detailed how the attacker managed their compromise across multiple environments.

At Ncerio, we continuously audit configuration settings for our clients. Our latest measurement for active-directory targets focused on compliance with established security baselines. The audit covered 1 audited active-directory target, identifying a total of 28 open findings. These were categorized by severity: 14 high, 9 medium, and 5 low.

The top gaps identified highlight specific misconfigurations that can elevate privilege or reduce visibility. One such gap involves the rule AD-ADMINNOEXP, which checks for privileged accounts with non-expiring passwords. The audit found one instance where this control was not enforced, potentially allowing persistent access if credentials are compromised.

Another critical finding relates to rule AD-ASREP, which ensures no accounts have Kerberos pre-authentication disabled. This configuration makes accounts roastable via the AS-REP roasting attack vector. One account in the estate lacked this protection, exposing it to offline password cracking attempts that do not trigger immediate alerting mechanisms.

The third notable gap concerns rule AD-ACCTOP, which regulates membership within the Account Operators group. The audit indicated one instance where membership limits were not strictly maintained at the required level of zero extra operators, broadening the scope of accounts capable of modifying user attributes in certain contexts.

It is important to clarify that this measurement reflects routine, continuous auditing of our estate configuration. It does not imply that any audited target was affected by the Aurora incident or used AI tools for malicious purposes. The link between the news item and our data is strictly topical, concerning active-directory configuration exposure. The audit results are static data points from a specific point in time.

The presence of these 28 findings across 1 target indicates areas where security posture can be hardened. Each gap represents a deviation from best practices that could theoretically aid an attacker in lateral movement or persistence. Addressing these configurations reduces the overall attack surface regardless of external threats.

To mitigate the risks associated with privileged account management, readers should review their own active-directory policies this week. Specifically, verify that all administrative accounts have password expiration enabled and that Kerberos pre-authentication is enforced for all service accounts. These steps align with the controls identified in our audit findings and help prevent common escalation techniques.

Source: Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations — GBHackers
← all posts  ·  CVE feed