Your weekly security roundup is here. From emerging threats to practical security tips, we’ve curated insightful articles and resources worth your attention, click the titles below to learn more.
From our Blog:
From the web:
LastPass How-To:
Active Directory in 2026: what your business needs to know
Active Directory (AD) powers more than 90% of enterprise networks. It controls who gets in, what they can access, and how your entire organization operates. That also makes it the #1 target for attackers.
Hackers go after AD because it holds the keys to the kingdom. Once inside, they escalate privileges, deploy ransomware, and can cripple operations in hours. The 2024 Change Healthcare attack — the most expensive cyberattack in U.S. history — started with a single server without MFA and ended with $2.3 billion in damages.
And if you're a small business thinking you're not a target? Think again. 88% of ransomware incidents involve SMBs.
What's new in 2026
Microsoft is deprecating RC4 encryption for Kerberos authentication and phasing out NTLM — both longtime attack vectors. Kerberoasting attacks have increased 100% year over year, making these updates critical. If you haven't updated your domain controllers or audited your service accounts, now is the time.
How to protect your AD environment
The strongest defense combines Microsoft's Enterprise Access Model, PIM/PAM for just-in-time privileged access, and LastPass to block credential-based attacks — a layered approach that keeps threat actors out even when they try hardest.
Want the full breakdown, including architecture, 2026 update timelines, and step-by-step security guidance? Read the complete article on our Blog: Active Directory (2026): what it is, what's new, and the must-know updates to keep your business safe
Want our latest security content delivered every week? Click Follow on the right-hand side and never miss an update.