daily cyber × ai intelligence

index

tagged

[spring-ring]

2 editions · 2 items

September 3, 2026

  • Spring Ring's Teams vishing ends in NTLM relay against domain controllers. Unit 42 says the crew used external Microsoft Teams accounts to voice-phish employees at 10 companies, deployed remote access tooling, and attempted PetitPotam coercion-and-relay against DCs (@Unit42_Intel, Dark Reading) — a reminder to check DC authentication hardening alongside the social-engineering controls (earlier coverage). · Threat Activity

in Ten Hours, Fifty Techniques: AI Agents Ran the Whole Ransomware Intrusion

September 1, 2026

  • Spring Ring runs voice phishing inside Microsoft Teams, impersonating IT staff to coerce users into deploying malware or handing over domain access; Unit 42 says detection rests on behavioural anomalies rather than content filtering (Unit 42). · Threat Activity

in Attackers Are Living in the Management Plane