Responder is a tool tracked across 4 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed November 26, 2025; most recent activity June 3, 2026.
Responder is a credential‑harvesting tool that poisons Windows name resolution protocols (NBNS, LLMNR, and MDNS) to capture authentication tokens such as NTLM hashes. It is widely used in Windows network environments to facilitate lateral movement by tricking hosts into authenticating to the attacker’s system. Its significance lies in exploiting insecure, legacy name-resolution mechanisms that remain in many networks, enabling rapid credential theft if not mitigated.
A newly identified flaw in Windows URI handlers can leak NTLMv2 hashes to attacker-controlled servers with a single link click. This vulnerability is related to CVE-2026-33829, which was patched in the Windows Snipping…
Mandiant has released rainbow tables that can crack credentials using the Net-NTLMv1 protocol within 12 hours. This legacy Microsoft authentication protocol has been known to expose users to credential theft for over 20…
Microsoft has announced that Windows Internet Name Service (WINS) will be removed from Windows Server starting in November 2034. System administrators are urged to prepare for this change, as WINS has been deprecated…
Microsoft announced plans to disable the NTLM authentication protocol by default in future Windows releases due to its security vulnerabilities that have been exploited in cyberattacks. NTLM, introduced in 1993, has…