Complex Mathematics

Microsoft Teams really could be bad for your (security) health – hackers spoof bosses, send fake messages, and more



  • Microsoft Teams flaws allowed message edits, spoofed alerts, and forged caller identities
  • Attackers could exploit these bugs for phishing, wire fraud, and malware delivery
  • Microsoft patched CVE-2024-38197; no user action needed post-October 2025 fixes

Experts have found Microsoft Teams contained multiple vulnerabilities whioch allowed threat actors to edit messages, spoof notifications, and change user names, opening it up for different phishing and social engineering attacks, putting users at risk of data theft, wire fraud, and malware/ransomware infections.

In a new report, experts from Check Point Research detailed the flaws in the popular online collaboration platform, noting the attackers could reuse unique identifiers in the Microsoft Teams messaging system, altering the content of previously sent messages without triggering the “Edited” label.





Source link