Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse

2026-04-01T19:23:38Z1c69909610482f7303e6eacd14cf4d03066bec6f2f3bba2eb6676197e35ac7d1
AI securityCNAME abuseCNAPPCVE-2026-20929DNSFalconKerberosMDRSIEMTycoon2FAagentic SOCauthentication relaydata securitydetection guidancemitigationphishing-as-a-servicesoftware supply chainsupply chaintrivy-action

What happened

CrowdStrike published multiple blog posts including a detection guide for CVE-2026-20929 — a Kerberos authentication relay technique that abuses DNS CNAME records — with detection and mitigation guidance. Other posts cover new product capabilities and research: AI agent security (Charlotte AI AgentWorks), Falcon product updates (Data Security, CNAPP adversary-informed risk prioritization, Next‑Gen SIEM third‑party EDR support, Agentic MDR), persistence of the Tycoon2FA phishing-as-a-service platform after a takedown, and an analysis of a trivy-action supply chain compromise that led to a steaI

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
crowdstrike_blog
Record identifier
1c69909610482f7303e6eacd14cf4d03066bec6f2f3bba2eb6676197e35ac7d1
Enrichment time
2026-04-01T19:23:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse · Baitaphish