Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

Microsoft Teams is being hacked to crack Office 365 accounts – here’s how to stay safe

  • May 17, 2023
Total
0
Shares
0
0
0


Researchers have discovered more ways to abuse Microsoft Teams to steal Office 365 user credentials by spreading malware, a new report has claimed.

New Proofpoint findings (opens in new tab) have claimed hackers can abuse the Tabs feature, used to synchronize between Microsoft Teams and Calendar, and the Teams API, to deliver droppers, or phishing pages, to unsuspecting victims.

The Tabs feature providers Teams users with quick access to different tools, such as OneDrive. As the default tabs can’t be moved around, users can get used to different ones and use them without second-guessing their benign nature. However, there is a way to move the default tabs, which cybercriminals could use to swap the legitimate ones with malicious ones. In one such example, Proofpoint says, a “Website” tab could point towards a malicious landing page where victims could end up giving away their Office 365 credentials.

Abusing meetings

The Website tab can also be changed to point to a file, which would get automatically downloaded on click. Cybercriminals could abuse this functionality to deliver droppers, the researchers said.

Microsoft Teams meeting invites can also be weaponized – when a member creates an online meeting (opens in new tab), the platform generates multiple links and sends to the invitees. With the help of Teams API calls, a threat actor would be able to swap the legitimate links for malicious ones.

Crooks can also go for a different approach, using Teams API or user interface to weaponize existing links in sent messages. In this scenario, the hyperlink that the victims receive wouldn’t change, just the URL behind it, making discovery even more difficult.

While the researchers are warning that these methods are dangerous, they stressed that in order to be effective, the attackers need to obtain a Teams account beforehand. 


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • Technology

France’s privacy watchdog eyes protection against data-scraping in AI action plan

  • May 17, 2023
View Post
Next Article
  • News

Good news, gamers: Nvidia and MediaTek are teaming up for new mobile GPUs

  • May 17, 2023
View Post
You May Also Like
View Post
  • News

Diablo 4’s authentication servers are down, preventing players from logging in

  • June 3, 2023
View Post
  • News

Can’t access your Street Fighter 6 deluxe or ultimate edition extras? Here’s a workaround

  • June 3, 2023
View Post
  • News

Gmail is adding more AI to help you find important emails faster

  • June 3, 2023
View Post
  • News

Star Wars: Knights of the Old Republic 2 – The Sith Lords Restored Content DLC is canceled on Switch

  • June 3, 2023
View Post
  • News

Microsoft says it’s curtains for Cortana in Windows 11 (and 10) – but that’s no surprise

  • June 3, 2023
View Post
  • News

It’s time for Windows Media Player to take on Apple Music for WWDC

  • June 3, 2023
View Post
  • News

Dodgy Champions League final streaming could be a serious own goal

  • June 3, 2023
View Post
  • News

Latest Apple VR headset leak gives us clues about how it might get used

  • June 3, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.