Microsoft has announced it will disable the legacy RC4 cryptographic cipher by default in Windows Kerberos authentication, marking a significant move to strengthen enterprise and government network security. The change, set to roll out in stages and be fully enforced by mid-2026, will require domain controllers on Windows Server 2008 and later to use stronger AES-SHA1 encryption by default. RC4 will only be permitted if explicitly configured by a domain administrator, addressing longstanding concerns about the cipher's vulnerabilities and its persistence due to legacy system dependencies.
Security experts have highlighted that RC4's continued use has enabled numerous attacks, including high-profile breaches such as the compromise of health giant Ascension, which exposed millions of patient records. The decision to deprecate RC4 follows mounting criticism, including calls from US lawmakers for regulatory scrutiny over Microsoft's default support for the outdated cipher. The move is widely regarded as one of Microsoft's most significant cryptographic cleanups in years, forcing organizations to modernize authentication systems and reduce exposure to attacks like Kerberoasting that exploit RC4 weaknesses.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft said the Kerberos update will reach domain controller defaults by mid-2026, so that only AES-SHA1 is allowed unless RC4 is explicitly configured. Organizations are being urged to identify and remediate legacy dependencies before the rollout takes effect.
Microsoft announced in December 2025 that it will deprecate RC4 in Windows Kerberos and disable it by default on Windows Server 2008 and later. The change is part of a phased rollout intended to push organizations toward stronger AES-SHA1 encryption while still allowing administrators to re-enable RC4 in limited cases.
In 2023, attackers exploited RC4-related weaknesses in Active Directory during the breach of Ascension, contributing to the compromise of millions of patient records and disruption of hospital operations. The incident became a prominent example of the risks posed by RC4 remaining enabled by default.
The RC4 stream cipher, originally developed by Ron Rivest in 1987, was leaked in 1994, after which its security weaknesses became widely known. Despite this, it continued to see broad use in Windows, SSL/TLS, and Kerberos environments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
wired.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcearstechnica.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.