{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Threat Talks - Your Gateway to Cybersecurity Insights","title":"Bad Successor: The Service Account Flaw to Watch","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/8ff1c49a\"></iframe>","width":"100%","height":180,"duration":1035,"description":"It was built to secure service accounts.\nInstead, it became the cleanest privilege-escalation vector of 2025.\nThey called it Bad Successor (A.K.A. CVE-2025-53779).\nA new “secure by design” feature in Windows Server 2025 -DMSA -was supposed to fix service account hygiene. Instead, it introduced a loophole where attackers could claim successor status, skip password requirements, and silently inherit elevated rights from any target account.\nIncluding domain admin.\nEven after Microsoft patched the issue, the deeper risk remains:\nService accounts are over-privileged, under-monitored, and dangerously trusted -and adversaries know it.\nThis isn’t a niche AD misconfiguration.\nIt’s a privilege-escalation design flaw hiding inside a security feature, and a warning shot for every environment leaning on default trust in the identity layer.\nWatch host Rob Maas, Field CTO at ON2IT, and Luca Cipriano, CTI & Red Team Lead at ON2IT break down how Bad Successor works, how attackers exploited it, and what a Zero Trust AD strategy actually looks like in 2025.\nKey Topics Covered\n• How a security upgrade became a privilege-escalation vector.\n• Why service account security failures create invisible attack paths.\n• The real DMSA abuse chain: child objects → successor claim → domain admin.\n• Zero Trust defenses for AD: permissions, logging, rotation, least privilege.\nGot your attention?\nSubscribe to Threat Talks and turn on notifications for deep dives into the world’s leading cyber threats and trends.\nGuest and Host Links:\nRob Maas (Field CTO, ON2IT): https://threat-talks.com/the-hosts/\nLuca Cipriano (CTI & Red Team Lead, ON2IT): https://threat-talks.com/the-hosts/\nAdditional Resources\nThreat Talks: https://threat-talks.com/\nON2IT (Zero Trust as a Service): https://on2it.net/\nAMS-IX: https://www.ams-ix.net/ams\n🔔 Follow and Support our channel! 🔔\n=== \n► YOUTUBE: https://youtube.com/@ThreatTalks\n► SPOTIFY: https://open.spotify.com/show/1SXUyUEndOeKYREvlAeD7E\n► APPLE:...","thumbnail_url":"https://img.transistorcdn.com/zxiRQtIn39fLuEqIC458HdYTjdufBy-QMdJtCYFz97Y/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8xN2Q1/NGE1NjBhYWY0ZmY5/NzEyODA5OGU3NDdi/MmNmYi5qcGc.webp","thumbnail_width":300,"thumbnail_height":300}