After years of cyberattacks, Microsoft cripples RC4 and forces networks to adopt stronger encryption immediately


  • RC4 has been exploited in high-profile attacks on Windows enterprise networks
  • Kerberoasting exploits weaknesses in Active Directory, allowing attackers to crack passwords offline
  • AES-SHA1 requires thousands of times more resources than RC4 for cracking

Microsoft is taking steps to disable RC4, an encryption built into Windows authentication for more than two decades.

The decision comes after years of documented abuse, repeated warnings from security researchers, and several high-impact breaches related to its continued availability.



Leave a Comment

Your email address will not be published. Required fields are marked *