Enterprise Security Intelligence

InsecurePlanet

PKI Security

Security current events, PKI risk, identity threats, and enterprise cybersecurity explained for the people who operate real systems.

CISA KEV
Editorially reviewed
Patch Tuesday
Monthly coverage
ADCS · CDP · PKI
Deep advisory content

Security Intelligence

Current Enterprise Security and PKI Topics

Source-backed security, PKI, certificate, identity, and post-quantum cryptography topics selected for enterprise relevance. Articles are reviewed before publication and include source attribution.

ADCS

ESC8 NTLM Relay and ADCS Web Enrollment: Enterprise Exposure, Detection, and Mitigation

Jun 16, 20268 min

ESC8 is a documented ADCS exposure pattern involving NTLM relay to HTTP-based certificate enrollment endpoints. We explain the exposure conditions, detection opportunities, and the configuration changes that eliminate the risk.

Read Brief
PKI

Microsoft Announces Mandatory CA Enforcement for Azure AD Certificate-Based Auth

Jun 12, 20266 min

Starting August 2026, Azure AD will enforce strict CA binding for certificate-based authentication. We explain what changes, which configurations break, and how to audit your tenant before the deadline.

Read Brief
ADCS

ESC1 Through ESC13: The Complete ADCS Misconfiguration Remediation Roadmap

Jun 9, 202612 min

A prioritized remediation roadmap for all known ADCS escalation paths — ESC1 through ESC13. Includes detection queries, remediation steps, and a risk-ranked order of operations for enterprise environments.

Read Brief
Identity

PKI and Zero Trust: Why Certificate-Based Device Trust Is Non-Negotiable

Jun 5, 20269 min

Zero Trust architecture depends on strong device and user identity. This brief explains why a healthy PKI is foundational — and what breaks when it is not.

Read Brief
PKI

OCSP Stapling and CRL Caching: Why Your Revocation Infrastructure Matters for Zero Trust

Jun 2, 20266 min

Revocation checking is often the weakest link in Zero Trust certificate validation. We examine OCSP stapling, CRL caching behavior, and how to design revocation infrastructure that actually works under load.

Read Brief
Identity

Kerberos PKINIT: Certificate-Based Authentication in Active Directory

May 28, 202615 min

How Kerberos PKINIT works, how to configure it, and how to validate your deployment. Includes common failure modes, revocation checking behavior, and hybrid Azure AD CBA considerations.

Read Brief

PKI Trust Hierarchy — Reference Architecture

PKI & Digital Trust

PKI and Certificate Security

In-depth coverage of Active Directory Certificate Services, certificate template security, revocation infrastructure, and certificate-based authentication — for the administrators who build and maintain enterprise PKI.

CA Hierarchy

Root CA & Subordinate CA Architecture

Design, deploy, and harden two-tier and three-tier PKI hierarchies for enterprise environments.

Explore
ADCS Templates

Certificate Template Security

Audit and remediate ESC1–ESC8 misconfigurations in Active Directory Certificate Services.

Explore
CDP / AIA / OCSP

Revocation Infrastructure

CRL distribution points, AIA extensions, and OCSP responder configuration and troubleshooting.

Explore
EAP-TLS / 802.1X

Certificate-Based Network Auth

Cisco ISE, NPS, and 802.1X certificate chain configuration for wired and wireless environments.

Explore

CISA KEV · Patch Tuesday · Enterprise Advisory

Selected Enterprise-Relevant Vulnerability Intelligence

Curated vulnerability, PKI, identity, and infrastructure security items selected for enterprise relevance. Content is reviewed editorially and updated on a scheduled basis.

Last editorial review: June 22, 2026

Selected CISA KEV and Enterprise-Relevant Vulnerability ItemsCISA Known Exploited Vulnerabilities
CVE-2025-47984
Windows LDAP ServerCritical

Heap buffer overflow enabling unauthenticated RCE on domain controllers — actively exploited.

Source: CISA KEV / MSRC

Nov 19, 2025
CVE-2024-49112
Windows LDAPCritical

Remote code execution in Windows LDAP — unauthenticated attacker can execute code on LDAP servers.

Source: CISA KEV / MSRC

Dec 10, 2024
CVE-2024-38063
Windows TCP/IPCritical

RCE via malformed IPv6 packets — no user interaction required, exploitable pre-authentication.

Source: CISA KEV / MSRC

Aug 13, 2024
View full KEV tracker

For authoritative current vulnerability status, review the original vendor advisory or the CISA Known Exploited Vulnerabilities Catalog.

MSFT-PATCH-TUESDAY

Microsoft Patch Tuesday

Monthly breakdown of Microsoft security updates — critical patches, ADCS vulnerabilities, and Windows Server risk.

View Topics
GLOBAL-THREAT-FEED

World Wide Threats

Nation-state campaigns, ransomware targeting enterprise infrastructure, and identity-based attack patterns.

View Topics

Advisory Services

Microsoft ADCS & Enterprise PKI Services

Hands-on advisory for organizations that need to assess, fix, and mature their PKI and identity security posture. Delivered by practitioners who work in enterprise environments every day.

Microsoft ADCS Health Check

Comprehensive review of your ADCS deployment — CA configuration, template permissions, and security posture.

Learn More

Enterprise PKI Security Assessment

End-to-end assessment of your PKI hierarchy, trust anchors, issuance policies, and operational controls.

Learn More

Certificate Template Review

Audit of all certificate templates for ESC1–ESC8 misconfigurations and over-permissive enrollment rights.

Learn More

PKI Migration Planning

Architecture and migration planning for CA consolidation, SHA-1 deprecation, and cloud PKI transitions.

Learn More

CRL / CDP / AIA Troubleshooting

Diagnosis and remediation of CRL distribution point failures and OCSP responder issues.

Learn More

Cisco ISE & EAP-TLS Certificate Support

Certificate chain configuration, RADIUS deployment, and EAP-TLS troubleshooting for Cisco ISE.

Learn More

Certificate Lifecycle Management Advisory

Strategy and tooling for certificate inventory, expiration monitoring, and renewal automation.

Learn More
Free Resource

Download the Free ADCS Security Checklist

A practical checklist for auditing your Active Directory Certificate Services deployment — covering template permissions, CA configuration, CDP/AIA paths, and common misconfigurations.

CA configuration & role separation
Certificate template permissions audit
CDP / AIA / OCSP path validation
ESC1–ESC8 misconfiguration checks
Auto-enrollment & GPO settings
CRL validity period & overlap

Security Brief

Subscribe to the InsecurePlanet Security Brief

Weekly coverage of CISA advisories, exploited vulnerabilities, Patch Tuesday, and PKI security news — written for enterprise engineers, not executives.

No spam. Unsubscribe anytime.