This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
payloadforge.io
did:plc:ewq4er2qjtqov34en6wvsgqc
CertiGhost (CVE-2026-54121) went public on 24 July from H0j3n and Aniq F. I planned a few minutes running their PoC in my Ludus lab and lost the weekend. The bug gets AD CS to trust identity data from a host the requester picks.
https://gist.github.com/H0j3n/a5ef2609b5f2944ac2390a191a534c26
2026-07-27T13:02:03.267Z