CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

dMSA Ouroboros: Self-Sustaining Credential Extraction in Windows Server 2025

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 700

As cited

Copy frozen at (site build).

identity access

dMSA Ouroboros: Self-Sustaining Credential Extraction in Windows Server 2025

Researchers discovered dMSA Ouroboros, a credential extraction technique that exploits delegated permissions in fully patched Windows Server 2025 domains. The attack is self-sustaining and persists despite standard remediation attempts, requiring only standard permissions to execute.

Why it matters: Active Directory administrators and identity teams need to understand this attack vector because it bypasses typical security controls and remediation processes, allowing attackers to maintain persistent credential access in core infrastructure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

identity access

dMSA Ouroboros: Self-Sustaining Credential Extraction in Windows Server 2025

Researchers discovered dMSA Ouroboros, a credential extraction technique that exploits delegated permissions in fully patched Windows Server 2025 domains. The attack is self-sustaining and persists despite standard remediation attempts, requiring only standard permissions to execute.

Why it matters: Active Directory administrators and identity teams need to understand this attack vector because it bypasses typical security controls and remediation processes, allowing attackers to maintain persistent credential access in core infrastructure.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary