Product
Microsoft Teams
- First Reported
- Jun 24, 2026
- Latest Reported
- Oct 6, 2026
Reported Context (7)
- the real story. Managed ISPM defines the target configuration across Entra ID, Exchange, SharePoint and Teams and manages Conditional Access with pre-deployment impact analysis. From there, it keeps watching, Why the SMB1001 Cybersecurity Standard Is Designed for Small Businesses
- networks. Attackers commonly posed as internal IT support and contacted employees through external Microsoft Teams accounts or voice calls, including calls to personal phones. ReliaQuest Report Tracks Top Attacker Techniques in June–August 2026
- The first phase, observed in March and April, relied on SEO-poisoned websites distributing trojanized Microsoft Teams MSI installers. These installers deployed a multi-stage PowerShell loader that communicated with TerminalFix Lures and Lorem Ipsum Loader Deploy a Covert Tunneling Implant
- Threat actors are increasingly combining spam bombing with Microsoft Teams vishing and then steering victims toward legitimate remote support and remote access tooling (such as Quick Assist and in some cases other ThreatLabz Report: Ransomware Data Theft Surges as Attackers Target High-Impact Employees
- TeamFiltration's default configuration includes a hardcoded user agent string from a 2020 Microsoft Teams desktop client - a non-common version these days: TeamFiltration Campaign Password-Sprays Forgotten Microsoft 365 Service Accounts in Chile
CVE (52)
Malware (18)
People (9)
Threat Actors (20)
MITRE ATT&CK (27)
Vendors (34)
Products (63)
Tools (13)
Industries (8)
Countries (12)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.