Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse
2026-04-01T19:23:38Z•1c69909610482f7303e6eacd14cf4d03066bec6f2f3bba2eb6676197e35ac7d1
AI securityCNAME abuseCNAPPCVE-2026-20929DNSFalconKerberosMDRSIEMTycoon2FAagentic SOCauthentication relaydata securitydetection guidancemitigationphishing-as-a-servicesoftware supply chainsupply chaintrivy-action
What happened
CrowdStrike published multiple blog posts including a detection guide for CVE-2026-20929 — a Kerberos authentication relay technique that abuses DNS CNAME records — with detection and mitigation guidance. Other posts cover new product capabilities and research: AI agent security (Charlotte AI AgentWorks), Falcon product updates (Data Security, CNAPP adversary-informed risk prioritization, Next‑Gen SIEM third‑party EDR support, Agentic MDR), persistence of the Tycoon2FA phishing-as-a-service platform after a takedown, and an analysis of a trivy-action supply chain compromise that led to a steaI
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- crowdstrike_blog
- Record identifier
- 1c69909610482f7303e6eacd14cf4d03066bec6f2f3bba2eb6676197e35ac7d1
- Enrichment time
- 2026-04-01T19:23:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.