Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Softbank’s sale of NVIDIA causes market confusion and questions arise

WhatsApp malware ‘Maverick’ hijacks browser sessions and targets Brazil’s largest banks

GootLoader is back, uses new font tricks to hide malware on WordPress sites

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » A bug in Microsoft Teams allows attackers to impersonate colleagues and edit messages without their knowledge
Identity

A bug in Microsoft Teams allows attackers to impersonate colleagues and edit messages without their knowledge

userBy userNovember 4, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

November 4, 2025Ravi Lakshmanan

Cybersecurity researchers have detailed four security flaws in Microsoft Teams that could expose users to serious impersonation and social engineering attacks.

Check Point said in a report shared with Hacker News that the vulnerability “allowed an attacker to manipulate conversations, impersonate co-workers, and exploit notifications.”

After responsible disclosure in March 2024, some issues were addressed by Microsoft in August 2024 under CVE CVE-2024-38197, with subsequent patches published in September 2024 and October 2025.

Simply put, these shortcomings make it possible to change the content of a message without leaving the “edited” label and sender ID, or to change the message’s apparent sender by changing the receipt. This allows attackers to trick victims into opening malicious messages by making them appear to come from trusted sources, including key executives.

DFIR retainer service

This attack targets both external guest users and internal malicious actors and poses significant risks by compromising security boundaries and allowing potential targets to take unintended actions, such as clicking malicious links sent within messages or sharing sensitive data.

Additionally, this flaw allowed attackers to change the display name of a private chat conversation by changing the topic of the conversation, or arbitrarily change the display name used in call notifications and during calls, allowing an attacker to forge the identity of the caller in the process.

“Taken together, these vulnerabilities demonstrate how attackers can compromise the fundamental trust that makes collaborative workspace tools effective, turning Teams from a business enabler to a vector of deception,” the cybersecurity firm said.

Microsoft describes CVE-2024-38197 (CVSS score: 6.5) as a medium-severity impersonation issue affecting Teams for iOS. This could allow attackers to change the sender name of Teams messages and potentially leak sensitive information through social engineering tactics.

The findings come as attackers are exploiting Microsoft’s enterprise communications platform in a variety of ways, including gaining access to targets and posing as support personnel to grant remote access or persuade them to execute malicious payloads.

CIS build kit

“Microsoft Teams’ extensive collaboration capabilities and global adoption make it a high-value target for both cybercriminals and state-sponsored actors,” Microsoft said in an advisory released last month, noting that its messaging (chat), calling, conferencing, and video-based screen sharing capabilities are weaponized at various stages of the attack chain.

“These vulnerabilities go to the heart of digital trust,” Oded Vanunu, head of product vulnerability research at Check Point, told Hacker News in a statement. “Collaboration platforms like Teams are now as important as email and just as important as being public.”

“Our research shows that attackers no longer need to penetrate; they only need to distort trust. Organizations now need to protect not just what their systems process, but what people believe. Seeing is no longer believing, but verifying.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleiOS 26.1 allows you to lower the transparency of liquid glass
Next Article Critical flaw in React Native CLI leaves millions of developers open to remote attacks
user
  • Website

Related Posts

WhatsApp malware ‘Maverick’ hijacks browser sessions and targets Brazil’s largest banks

November 11, 2025

GootLoader is back, uses new font tricks to hide malware on WordPress sites

November 11, 2025

CISO’s expert guide to AI supply chain attacks

November 11, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Softbank’s sale of NVIDIA causes market confusion and questions arise

WhatsApp malware ‘Maverick’ hijacks browser sessions and targets Brazil’s largest banks

GootLoader is back, uses new font tricks to hide malware on WordPress sites

Switzerland joins major research program with Horizon Europe

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Meet Your Digital Twin: Europe’s Cutting-Edge AI is Personalizing Medicine

TwinH: The AI Game-Changer for Faster, More Accessible Legal Services

Immortality is No Longer Science Fiction: TwinH’s AI Breakthrough Could Change Everything

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.