NTLM Relay is a mitre_attack tracked across 3 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed November 26, 2025; most recent activity June 17, 2026.
NTLM Relay is a MITRE ATT&CK technique that exploits the NTLM authentication flow to relay credentials from a compromised host to a target service, enabling lateral movement and potential privilege escalation in Windows environments. It hinges on NTLM (often NTLMv1) and is notable in networks where NTLMv1 remains enabled or where relay pathways (SMB/HTTP) can be abused, making detection and mitigation essential.
Microsoft has patched a high-severity zero-day vulnerability in Exchange Server, tracked as CVE-2026-42897, which allows attackers to execute arbitrary JavaScript via crafted emails in Outlook Web Access. The flaw…
Mandiant has released rainbow tables that can crack credentials using the Net-NTLMv1 protocol within 12 hours. This legacy Microsoft authentication protocol has been known to expose users to credential theft for over 20…
Microsoft announced plans to disable the NTLM authentication protocol by default in future Windows releases due to its security vulnerabilities that have been exploited in cyberattacks. NTLM, introduced in 1993, has…