October 5, 2025 | 06:00

Why Every Windows AD Should Be Kept Offline

Not only since my seven security tips1 have I been getting questions about why I prefer to keep Windows and an Active Directory2 offline. That may sound inflexible, and in an era of AI-generated cybersecurity slop3 I may look like an outsider. So in today’s blog post I provide more context, explain the technical background, and lay out how ransomware works. Read more

July 3, 2025 | 10:20

Hacking WSUS

If you have an own PKI in your AD, you may stop reading and move on. Nothing to see here. My gut however tell me, many mid-sized companies don’t have one and are at the mercy of Alex Neff’s Python script.1 Wsuks2 positions itself as man-in-the-middle between a Windows Update Server (WSUS) and the various servers/clients. Read more

© 2025 Tomas Jakobs - Imprint and Legal Notice

Support this blog - Donate a Coffee