<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Microsoft-Teams on CuraSec</title><link>https://curasec.metacog.co.kr/tags/microsoft-teams/</link><description>Recent content in Microsoft-Teams on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 31 Aug 2026 18:00:29 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/microsoft-teams/index.xml" rel="self" type="application/rss+xml"/><item><title>Spring Ring campaign uses Teams voice phishing to hit domain controllers</title><link>https://curasec.metacog.co.kr/insights/2026-08-31-spring-ring-an-inside-look-at-voice-phishing-campaigns-in-mi/</link><pubDate>Mon, 31 Aug 2026 18:00:29 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-31-spring-ring-an-inside-look-at-voice-phishing-campaigns-in-mi/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No CVE or patch required; the attack path abuses Teams social engineering rather than a software flaw, so review Teams external-access settings and restrict who can initiate calls from outside the tenant.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active enterprise campaign targeting domain controllers via Teams vishing — hunt for anomalous Teams call activity from external tenants followed by process execution or lateral movement, and review Unit 42&amp;rsquo;s published TTPs for detection rule development.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Campaign targets enterprise domain controllers through a trusted communication channel (Teams), raising both breach-risk and vendor-trust questions — brief IT leadership and consider tightening external Teams communication policies this quarter.&lt;/li>
&lt;/ul></description></item><item><title>Microsoft Teams adds admin control to block external bots in meetings</title><link>https://curasec.metacog.co.kr/insights/2026-08-25-microsoft-teams-now-lets-admins-block-external-bots-from-mee/</link><pubDate>Tue, 25 Aug 2026 11:39:54 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-25-microsoft-teams-now-lets-admins-block-external-bots-from-mee/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Enable the Teams meeting protection policy in your tenant admin settings to prevent uninvited external bots from joining meetings — worth configuring this quarter as part of M365 hardening.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>SynkLoader malware spread via Microsoft Teams phishing for cred theft</title><link>https://curasec.metacog.co.kr/insights/2026-08-22-new-synkloader-malware-pushed-in-microsoft-teams-phishing-ca/</link><pubDate>Sat, 22 Aug 2026 11:32:44 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-22-new-synkloader-malware-pushed-in-microsoft-teams-phishing-ca/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No exploitable software vulnerability here — the attack surface is social engineering over Teams external messages. Review whether your Teams tenant restricts external/guest messaging and confirm phishing-resistant MFA is enforced for all accounts.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Active campaign using Teams external messages to deliver a fake lock screen overlay for credential harvesting; build or tune detections for Teams-sourced phishing followed by unusual lock screen events and credential access patterns in EDR telemetry.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Confirms Microsoft Teams is an active credential-phishing vector, useful context for awareness training priorities, but no corroborating signals or sector-specific targeting reported that would require immediate leadership action.&lt;/li>
&lt;/ul></description></item></channel></rss>