September 3, 2026
- Spring Ring's Teams vishing ends in NTLM relay against domain controllers. Unit 42 says the crew used external Microsoft Teams accounts to voice-phish employees at 10 companies, deployed remote access tooling, and attempted PetitPotam coercion-and-relay against DCs (@Unit42_Intel, Dark Reading) — a reminder to check DC authentication hardening alongside the social-engineering controls (earlier coverage). · Threat Activity
in Ten Hours, Fifty Techniques: AI Agents Ran the Whole Ransomware Intrusion