#NTLM
Oh hey. We announced *when* we're disabling NTLM by default.

Hint: soon.
Advancing Windows security: Disabling NTLM by default - Windows IT Pro Blog
Learn how Windows is moving toward an NTLM-independent future with enhanced auditing, Kerberos enhancements, and a phased roadmap.
techcommunity.microsoft.com
January 29, 2026 at 10:36 PM
Jerry did a nice write up on how to take on NTLM in your environment.

We've got some Very Fun updates coming out in the next little while on this front too.
Active Directory Hardening Series - Part 8 – Disabling NTLM | Microsoft Community Hub
Hi All.  Jerry Devore back again to continue talking about hardening Active Directory.  This time I want to discuss disabling NTLM or more likely...
techcommunity.microsoft.com
January 15, 2026 at 5:40 PM
Oh by the way
December 6, 2024 at 1:08 AM
Wine 11.15 is out with ARM64EC build support in MinGW mode, local NTLM authentication, more BCrypt KDF algorithms, and WindowsCodecs improvements.
linuxiac.com/wine-11-15-r...

#OpenSource
Wine 11.15 Released with ARM64EC and Local NTLM Support
Wine 11.15 is out with ARM64EC build support in MinGW mode, local NTLM authentication, more BCrypt KDF algorithms, and WindowsCodecs improvements.
linuxiac.com
August 8, 2026 at 12:55 PM
Huh. I wish killing off NTLM was as easy as this in real life.

github.com/SteveSyfuhs/...
March 29, 2026 at 9:46 PM
Part 8053 of eleventy billion on our path to killing NTLM: way way way way way better auditing.

support.microsoft.com/en-us/topic/...
Overview of NTLM auditing enhancements in Windows 11, version 24H2 and Windows Server 2025 - Microsoft Support
Summary of new auditing features and deployment details
support.microsoft.com
July 13, 2025 at 4:35 PM
How long until l0phtcrack gets run against Big Balls’ NTLM hashes
DOGE has been sending their mass emails from a misconfigured server, causing DOGE emails to fail SPF (Sender Policy Framework) validation.

This means that agencies are probably marking DOGE emails as spam.
I am hearing from gov employees who got the OPM email but won't open it because it seems so shady. Things are going great.
February 22, 2025 at 10:37 PM
Look, I'm not going to take credit for Curl disabling NTLM by default...

Wait, yes, I am. Just a smidge.

github.com/curl/curl/pu...
build: make NTLM disabled by default by bagder · Pull Request #20698 · curl/curl
NTLM has weak security and does not work over HTTP/2 or HTTP/3. Enable in cmake or configure to get support for it. (Tentatively to get merged in the coming feature window, late March 2026) docum...
github.com
February 24, 2026 at 4:31 AM
Something something NTLM
You're trying your best, Steve. That's all we ask.
January 8, 2026 at 7:53 PM
Handwritten rental agreements are basically just NTLM
July 29, 2025 at 10:10 PM
She will learn to say "NTLM is blech" soon.
August 25, 2025 at 3:44 AM
Think NTLM relay is a solved problem? Think again.

Relay attacks are more complicated than many people realize. Check out this deep dive from Elad Shamir on NTLM relay attacks & the new edges we recently added to BloodHound. ghst.ly/4lv3E31
April 8, 2025 at 11:00 PM
I guess the news is out. I'm killing NTLM at Bluehat next week.
October 3, 2023 at 3:36 PM
CVE-2026-76654: Subpath symlinking on Windows nodes permits NTLM coercion -
CVE-2026-76654: Subpath symlinking on Windows nodes permits NTLM coercion · Issue #142098 · kubernetes/kubernetes
CVSS Rating: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N - Medium (5.8) An NTLM coercion vulnerability exists on Windows nodes when the subPath supplied in a pod's volumeMounts is set to a symboli...
github.com
September 25, 2026 at 3:06 PM
Wheeeeeeeeeeeeeeeeee
June 3, 2024 at 5:52 PM
Microsoft announced that it will disable the 30-year-old NTLM authentication protocol by default in upcoming Windows releases due to security vulnerabilities that expose organizations to cyberattacks.
Microsoft to disable NTLM by default in future Windows releases
Microsoft announced that it will disable the 30-year-old NTLM authentication protocol by default in upcoming Windows releases due to security vulnerabilities that expose organizations to cyberattacks.
www.bleepingcomputer.com
January 30, 2026 at 5:09 PM
That reminds me. What were the terms of our NTLM bet, again?
March 8, 2026 at 1:40 AM
"Why are you so motivated to kill NTLM??"

"I made a bet with Ned and I don't intend on losing it"
I will take the bet that NTLM will be disabled by default within a specific period of time.

Name your terms.
April 29, 2025 at 7:50 PM
This week's special guest co-host is @rgblights.bsky.social, who'll be joining @metlstorm.risky.biz and I to talk through the week's news. Then we'll chat with SpecterOps about new features they've built in Bloodhound to address NTLM-related risks to your network

NTLM.. still a problem

In 2025 :(
March 11, 2025 at 10:38 PM
Hey, Microsoft is getting rid of RC4-based NTLM key derivation! www.microsoft.com/en-us/window...
Beyond RC4 for Windows authentication
As organizations face an evolving threat landscape, strengthening Windows authentication is more critical than ever.
www.microsoft.com
December 10, 2025 at 3:04 PM
ANNOUNCMENT: MITIGATING NTLM RELAY ATTACKS BY DEFAULT...

HIGHLY RECOMMENDED READING

In Windows Server 2025, we've done a lot of work on our journey to prepare to deprecate NTLM in a future release of Windows. (NTLM is still there now...)

msrc.microsoft.com/blog/2024/12...
Mitigating NTLM Relay Attacks by Default | MSRC Blog | Microsoft Security Response Center California Consumer Privacy Act (CCPA) Opt-Out Icon
Mitigating NTLM Relay Attacks by Default
msrc.microsoft.com
December 11, 2024 at 5:09 PM
NTLM by a mile
December 11, 2025 at 4:16 AM
A new zero-day vulnerability has been discovered that allows attackers to capture NTLM credentials by simply tricking the target into viewing a malicious file in Windows Explorer.
New Windows zero-day exposes NTLM credentials, gets unofficial patch
A new zero-day vulnerability has been discovered that allows attackers to capture NTLM credentials by simply tricking the target into viewing a malicious file in Windows Explorer.
www.bleepingcomputer.com
December 6, 2024 at 4:32 PM