Spring Ring turns Microsoft Teams help-desk calls into an identity attack path
Published 09 Sep 2026 · Severity: high
Unit 42 disclosed Spring Ring on 31 August 2026: external Microsoft Teams identities impersonated IT support and moved victims from chat to voice calls, remote-control tooling or custom malware. One observed path attempted NTLM relay against a domain controller. This is social engineering, not a Microsoft product vulnerability.