Get a Pentest and security assessment of your IT network.

Cyber Security

Single Malicious GIF Opened Microsoft Teams to Nasty Attack

Microsoft has fixed a subdomain takeover vulnerability in its collaboration platform Microsoft Teams that could have allowed an inside attacker to weaponize a single GIF image and use it to pilfer data from targeted systems. Microsoft neutralized the threat last Monday, updating misconfigured DNS records, after researchers reported the vulnerability on March 23. The attack involves malicious actors being able to abuse a. JSON Web Token ( authtoken ) and a second skype token . The vulnerability can also be sent to groups (a group) which makes it easier for an attacker to get control over users faster and fewer users.

Source: https://threatpost.com/single-malicious-gif-opened-microsoft-teams-to-nasty-attack/155155/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security