A proof-of-concept (PoC) attack has been crafted by a cybersecurity firm for a design flaw in the Active Directory service, which would allow an attacker to modify the victims password even if some protection measures are in place.Security researchers from Israeli firm Aoroto found that using a freely available penetration tool, an attacker could steal an authentication component from an employees device.The component is called NTLM hash, which relies on weak cryptography, acts a…