#NTLM
There and Back Again: An Operators Guide on NTLM Relaying Egress
There and Back Again: An Operators Guide on NTLM Relaying Egress
specterops.io
September 28, 2026 at 12:42 AM
「ドメイン参加してないPCはNTLMしか使えない」——私もずっとそう思い込んでいました。

DC・ファイルサーバー・ワークグループPCの最小構成で、NTLM受信を止めた状態からKerberosでアクセスできるかを実機で検証。イベントID 4624/4768/4769とklistで、実際にどちらの認証が使われたかを1回ずつ裏取りしています。

Entra ID参加端末やAzure Filesなど、AD非参加の主体がKerberosを使う構成が増えている今こそ整理しておきたい話です。
https://youtu.be/NbVy-F11t2M
September 27, 2026 at 10:20 AM
『ドメイン参加してないPCからのアクセスはNTLMでいいでしょ』長く思い込んでた話題を、実環境で監査ログを見ながら検証してみました。
https://www.youtube.com/watch?v=NbVy-F11t2M
#Windows #ActiveDirectory
September 27, 2026 at 9:31 AM
CVE-2026-76654: Subpath symlinking on Windows nodes permits NTLM coercion -
CVE-2026-76654: Subpath symlinking on Windows nodes permits NTLM coercion · Issue #142098 · kubernetes/kubernetes
CVSS Rating: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N - Medium (5.8) An NTLM coercion vulnerability exists on Windows nodes when the subPath supplied in a pod's volumeMounts is set to a symboli...
github.com
September 25, 2026 at 10:07 PM
CVE-2026-76654: Subpath symlinking on Windows nodes permits NTLM coercion -
CVE-2026-76654: Subpath symlinking on Windows nodes permits NTLM coercion · Issue #142098 · kubernetes/kubernetes
CVSS Rating: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N - Medium (5.8) An NTLM coercion vulnerability exists on Windows nodes when the subPath supplied in a pod's volumeMounts is set to a symboli...
github.com
September 25, 2026 at 3:06 PM
NTLM vs Kerberos vs LDAP: cuál elegir para tu e-commerce

NTLM vs Kerberos vs LDAP: ¿cuál protege mejor los datos de tu e-commerce? Comparamos cifrado, tickets y vulnerabilidades reales antes de elegir

#ntlm #kerberos #ldap #activedirectory #autenticación
NTLM vs Kerberos vs LDAP: cuál elegir para tu e-commerce
Comparamos los tres protocolos de autenticación más usados en Windows: cifrado, vulnerabilidades pass-the-hash y qué conviene para un e-commerce en 2026.
donweb.news
September 23, 2026 at 5:04 PM
Dan Lorenc at Chainguard posted this statement about #curl on LinkedIn...
September 23, 2026 at 5:51 AM
On a recent Incident response case, we encountered VMkatz.

"It extracts Windows secrets - NTLM hashes, DPAPI master keys, Kerberos tickets, cached domain credentials, LSA secrets, NTDS.dit, BitLocker keys - directly from VM memory snapshots and virtual disks, on the NAS, the hypervisor.." [1]
GitHub - nikaiw/VMkatz: Extract Windows credentials directly from VM memory snapshots and virtual disks
Extract Windows credentials directly from VM memory snapshots and virtual disks - nikaiw/VMkatz
github.com
September 22, 2026 at 4:46 AM
so tired of hearing 'just disable ntlm' for pass-the-hash.

ngl that's a pipe dream for most orgs with legacy crap.

the real problem is letting privileged accounts touch low-tier systems. if a DA's hash is on a dev laptop, you've already lost. it's about tiering, not one protocol.
September 22, 2026 at 2:30 AM
📢 NTLMScout : outil de reconnaissance des endpoints NTLM exposés sur Internet

L'outil exploite le fait qu'une négociation NTLM non authentifiée (message Type-1 NEGOTIATE) provoque en réponse un message Type-2 CHALLENGE qui divulgue…

🟡 vérification factuelle moyenne
#NTLM #ntlmscout #Cyberveille
NTLMScout : outil de reconnaissance des endpoints NTLM exposés sur Internet
L'outil exploite le fait qu'une négociation NTLM non authentifiée (message Type-1 NEGOTIATE) provoque en réponse un message Type-2 CHALLENGE qui divulgue de nombreuses informations internes Active Directory avant toute transmission de credential : Noms NetBIOS et DNS de l'hôte et du domaine Nom de la forêt AD et de l'arbre Version Windows (build OS mappé vers un nom lisible) Horloge serveur et…
cyberveille.ch
September 20, 2026 at 8:00 PM
📌 New .NET Framework Exploitation Primitive Enables Arbitrary File Writes and RCE via SOAP HTTP Client... https://www.cyberhub.blog/article/28692-new-net-framework-exploitation-primitive-enables-arbitrary-file-writes-and-rce-via-soap-http-client-proxies
New .NET Framework Exploitation Primitive Enables Arbitrary File Writes and RCE via SOAP HTTP Client Proxies
The video presents a security research talk by Piotr Bazydło, a principal vulnerability researcher at Watch Towel, detailing a new exploitation primitive in .NET Framework involving SOAP HTTP client proxies and WSDL imports. The vulnerability allows attackers to manipulate URLs passed to .NET’s WebRequest.Create method, enabling protocol switching from HTTP to file protocols, resulting in arbitrary file writes or NTLM relaying, with potential escalation to remote code execution (RCE). The attack surface was identified in 2024 during SharePoint reviews but gained broader relevance in July 2025 when Bazydło discovered unauthenticated WSDL import functionality in Barracuda Service Center, which dynamically generates and compiles SOAP client proxies from attacker-controlled WSDLs. Exploitation requires control over the WSDL’s service URL, SOAP method names, or input arguments, with successful RCE demonstrated in products like Barracuda, Ivanti Endpoint Manager, Umbraco 8, Microsoft PowerShell, and SQL Server Integration Services. Microsoft declined to patch the root issue, citing intended behavior, but vendors like Ivanti addressed specific instances (CVE-8.8). The research highlights risks in applications using ServiceDescriptionImporter or unvalidated WSDL inputs, with mitigation requiring protocol validation before proxy invocation.
www.cyberhub.blog
September 20, 2026 at 12:37 PM
ntlmscout - sends an NTLM Type-1 (NEGOTIATE) message across a wide range of transports, fully decodes the Type-2 (CHALLENGE) that comes back, and retrieves internal NetBIOS/DNS host and domain names, the AD forest, the OS build, t…

— from @ipurple (https://x.com/ipurple/status/2101299241993855064)
GitHub - boydhacks/ntlmscout
t.co
September 19, 2026 at 1:28 PM
Ghostlink from HackTheBox has an open MQTT broker used to coerce auth, NTLM relay into a hidden site, file read to a KeePass DB, a Gogs symlink write for a shell, and ADCS ESC11 for the domain.
HTB: Ghostlink
Ghostlink is built around a fictional threat group running its operations on a Windows domain controller, with a message broker quietly announcing infrastructure I can’t otherwise reach. I’ll subscribe to that broker anonymously to find internal sites, then publish a tampered health check message to coerce the host into authenticating to me. Relaying that authentication gets me into a restricted file sharing site, where an unchecked path in the download endpoint gives arbitrary file read, leading to a user’s registry hive and a password database. Those credentials unlock the Gogs instance, where a symbolic link flaw in the content API lets me overwrite a Git config and get a shell on the virtual machine hosting it. I’ll crack a password hash from the Gogs database to reach a domain account, and finish by relaying coerced machine account authentication to the certificate authority to get a certificate for the domain controller and dump the domain. In Beyond Root, I’ll show why the other certificate services path never had a chance, and reverse engineer the file sharing application.
0xdf.gitlab.io
September 15, 2026 at 9:51 PM
CVE-2026-91926 - Gss-ntlmssp: gss-ntlmssp: memory leak in ntlm_decode_target_info via duplicated av_pair entries in ntlm challenge
CVE ID : CVE-2026-91926

Published : Sept. 15, 2026, 11:49 a.m. | 26 minutes ago

Description : A flaw was found in gss-ntlmssp. A memory leak...
CVE-2026-91926 - Gss-ntlmssp: gss-ntlmssp: memory leak in ntlm_decode_target_info via duplicated av_pair entries in ntlm challenge
A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE message contains duplicated string-valued AV_PAIR entries. The parser allocates memory for each string value but does not free the previous allocation when the same AV_PAIR type appears more than once, …
cvefeed.io
September 15, 2026 at 1:39 PM
NTLM 廃止が現実味を帯びてきたんですね。1993年から Windows で使われてた認証。多くの組織が気づかずに使ってるケース、実は結構あるかもしれません。https://www.youtube.com/watch?v=0JP3hU-K7B0 #Windows #Azure
September 14, 2026 at 11:14 AM
WindowsのNTLM無効化で一番困るのは、BuffaroやI/Oデータのような雑な作りの家庭用NASを作ってきたところだろうな。まぁエンタープライズ向けも結構雑な作りなんだけど。
September 14, 2026 at 9:48 AM
NTLMは削除ではなく次期Windowsで既定無効へ。MicrosoftのFAQ28問を日本語で解説した動画

📎 - YouTube
https://youtu.be/0JP3hU-K7B0
September 14, 2026 at 9:43 AM
🔐 NTLMが次期Windowsで「既定で無効」へ動き出しました。

「うちはActive Directoryだから関係ない」は通用しません。DCに届かない・IPアドレス直打ち・非ドメイン参加——そんな場面で今日も静かにNTLMへ落ちています。

MicrosoftのFAQ 28問を1問ずつ日本語で追いかけました。次のリリースを待たず今すぐ着手できることも 👀

#Windows #セキュリティ

https://youtu.be/0JP3hU-K7B0
September 14, 2026 at 9:42 AM
Making NTLM-Relaying Relevant Again by Attacking Web Servers with WebRelayX
NTLM-Relaying in 2026 | SecCore GmbH
NTLM-Relaying is a common attack vector in internal networks. In this blog post, we will show that even in 2026, there are still many scenarios where NTLM-Relaying can be successfully performed, and we will provide some insights into how to mitigate these risks.
seccore.at
September 14, 2026 at 12:43 AM
NTLM廃止の公式FAQ28問を1問1スライドで日本語に

📎 Ebisuda Presentations
https://presentations.ebisuda.net/decks/ntlm-retirement-faq
September 13, 2026 at 1:42 PM
MicrosoftのNTLM廃止FAQ(28問・6セクション)を1問ずつ日本語で全部読む動画を出しました📖

NTLMは次期Windowsのメジャーリリースで「削除」ではなく「既定で無効」になる予定。手元のServer 2019/2022/2025やWin10/11はどう扱われ、何から壊れるのかを順に追っています。

メンバー先行公開中で、明日9/14 18:00に一般公開します。
https://youtu.be/0JP3hU-K7B0
September 13, 2026 at 1:34 PM