Identity & Access Microsoft Moves Closer to Disabling NTLM The next major Windows Server and Windows releases will have the deprecated authentication protocol disabled by default. Ionut ArghireFebruary 2, 2026
Endpoint Security Microsoft Disables Downloaded File Previews to Block NTLM Hash Leaks In files downloaded from the internet, HTML tags referencing external paths could be used to leak NTLM hashes during file previews. Ionut ArghireOctober 24, 2025
Vulnerabilities Fresh Windows NTLM Vulnerability Exploited in Attacks A Windows NTLM vulnerability patched in March has been exploited in attacks targeting government and private institutions. Ionut ArghireApril 18, 2025
Identity & Access Microsoft Rolls Out Default NTLM Relay Attack Mitigations Microsoft has rolled out new default security protections that mitigate NTLM relaying attacks across on-premises Exchange, AD CS, and LDAP services. Ionut ArghireDecember 10, 2024
Identity & Access New NTLM Hash Leak Attacks Target Outlook, Windows Programs Varonis finds one vulnerability and three attack methods that can be used to obtain NTLM hashes via Outlook and two Windows programs. Eduard KovacsJanuary 22, 2024
Identity & Access Microsoft Improving Windows Authentication, Disabling NTLM Microsoft is adding new features to the Kerberos protocol, to eliminate the use of NTLM for Windows authentication. Ionut ArghireOctober 16, 2023