1 story taggedwinrm.
Microsoft says attackers are cold-calling staff on Teams, talking them into a screen share, then walking straight through the network to domain controllers.