Microsoft's 6-year-old Zerologon patches use AES-CFB8 incorrectly. The novel Onelogon attack provides two ways to take over a vulnerable AD account in apx 30 minutes. #AESCFB8fail #WONTFIX https://softsec.link/woot26.onelogon @al3x-n3ff.bsky.social @hlt @cao




