Get a Pentest and security assessment of your IT network.

Cyber Security

Microsoft Teams Can Be Used to Download and Run Malicious Packages

The update mechanism as it is currently implemented in Microsoft Teams desktop app allows downloading and executing arbitrary files on the system. Multiple security researchers discovered that using the ‘update’ command for a vulnerable application it is possible to execute an arbitrary binary in the context of the current user. The same issue affects GitHub, WhatApp, and UiPath software for desktop computers but it can be used only to download a payload. With Microsoft Teams, a payload is added to its folder and executed automatically using either of the following commands: update.

Source: https://www.bleepingcomputer.com/news/security/microsoft-teams-can-be-used-to-download-and-run-malicious-packages/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security