Researchers used a GIF to prove they could access Microsoft Teams user data

Zoom isn’t the only video conferencing service attracting scrutiny from security researchers. Microsoft Teams, the technology giant’s professional collaboration tool, included a software bug that could have made it possible for hackers to steal data. Hackers could have used a malicious GIF to scrape user data from Microsoft Teams user accounts, spreading through an organization’s entire roster of employees who use the service, researchers from CyberArk announced Monday. The issue existed for three weeks between the end of February through mid-March, when much of the U.S. started to telework in response to the coronavirus pandemic. “The amount of data that goes into these applications is enormous and often includes confidential information from user names and passwords to top-secret business information – making them prime targets for attackers,” Omer Tsarfati, a CyberArk researcher, said in a blog post. CyberArk did not point to any evidence the issue had been exploited in […]

The post Researchers used a GIF to prove they could access Microsoft Teams user data appeared first on CyberScoop.

Continue reading Researchers used a GIF to prove they could access Microsoft Teams user data

Vulnerability allowed hijacking of Microsoft Teams account with a GIF

By Deeba Ahmed
Forget Zoom for a second it is Microsoft Teams service that was exposed to account take over vulnerability with just a GIF file.
This is a post from HackRead.com Read the original post: Vulnerability allowed hijacking of Microsoft Teams … Continue reading Vulnerability allowed hijacking of Microsoft Teams account with a GIF

Zoom Phishing Campaign Tricks People into Revealing Login Credentials

A new Zoom phishing campaign preys on people’s fears related to job security, tricking them into revealing credentials that criminals can abuse in a variety of ways. The practice of Zoom-bombing is still common across the world, even though the Z… Continue reading Zoom Phishing Campaign Tricks People into Revealing Login Credentials

New Zoom vulnerability lets hackers record any meeting anonymously

By Waqas
This Zoom vulnerability lets hackers record meetings even when host disables recording functionality for participants.
This is a post from HackRead.com Read the original post: New Zoom vulnerability lets hackers record any meeting anonymously
Continue reading New Zoom vulnerability lets hackers record any meeting anonymously

Phishers exploiting employees’ layoff, payroll concerns

A few days ago, we outlined several phishing campaigns going after Zoom and WebEx credentials of employees. Two new ones are trying to exploit their (at the moment very rational) fears by delivering fake “Zoom meeting about termination” ema… Continue reading Phishers exploiting employees’ layoff, payroll concerns

Smashing Security #175: Zoom deepfakes, Zardoz, and ‘Rona tracing

Will deepfake disguises hit a video conference near you, can Coronavirus-tracing apps be trusted, and should Facebook shut down anti-quarantine events?
All this and much more is discussed in the latest edition of the award-winning “Smashing Secur… Continue reading Smashing Security #175: Zoom deepfakes, Zardoz, and ‘Rona tracing