← All stories
● Covered by 1 source · 1 reportHigh impact

Mandiant Identifies Vulnerability in ADFS Certificate Management

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Manual ADFS certificate rotation may expose signing keys
  • Attackers can forge SAML tokens, bypassing MFA
  • Common enterprise configurations leave this vulnerability unaddressed

Introduction to Ghost Certificates

Mandiant's research on the 'Golden SAML' technique has highlighted significant vulnerabilities in Microsoft identity management.

The discovery during a recent red team engagement showed that certain configurations lead to active ADFS signing keys being left exposed.

Mechanism of the Vulnerability

When AutoCertificateRollover is disabled, and certificates are rotated manually, old certificates can still exist in Machine DPAPI, creating a 'ghost' record.

This configuration is prevalent in enterprise environments, allowing adversaries to exploit it without triggering alarms.

Impact of the Exploit

By accessing the exposed signing keys, attackers can authenticate as any user to SAML-federated applications, bypassing MFA and identity controls.

The low visibility of this attack method due to its avoidance of direct interactions with monitored components enhances its threat level.

Recommendations for Mitigation

Organizations should ensure that AutoCertificateRollover is enabled and conduct regular audits of their ADFS configurations.

Mandiant provides a detailed blueprint for defending against exploitation of this vulnerability, urging awareness and proactive measures.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Mandiant discovered that improper manual rotation of ADFS certificates can expose active signing keys in Machine DPAPI. This vulnerability allows attackers to forge SAML tokens and bypass authentication mechanisms, posing significant risks to enterprise security.