TeamsPhisher: Tool automatisiert Angriffe auf Teams-Schwachstelle

Über eine Schwachstelle in Teams können Angreifer Malware unterjubeln. Ein jetzt veröffentlichtes Tool macht diese Attacken noch einfacher.

heise online

Bottom line on the #TeamsPhisher #vulnerability - it's up to #enterprise #admins to #secure the platform by disabling #Teams messages from external tenants, or use "allow-listed" domains only.

Here's a good article from SC Media reporting on the topic: https://www.scmagazine.com/news/cloud-security/microsoft-teamsphisher-nothing-to-see-here

#malware #payloaddelivery #cyberthreats #cyber #cybersecurity #sysadmins #phishing

Microsoft on TeamsPhisher: ‘Nothing to see here’

Microsoft appears to have no plans to patch the vulnerability, which is now being used by red teams as a malicious payload delivery method.

SC Media