Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

Microsoft Teams really could be bad for your (security) health – hackers spoof bosses, send fake messages, and more

Tech Wavo by Tech Wavo
November 5, 2025
in Computers
0



  • Microsoft Teams flaws allowed message edits, spoofed alerts, and forged caller identities
  • Attackers could exploit these bugs for phishing, wire fraud, and malware delivery
  • Microsoft patched CVE-2024-38197; no user action needed post-October 2025 fixes

Experts have found Microsoft Teams contained multiple vulnerabilities whioch allowed threat actors to edit messages, spoof notifications, and change user names, opening it up for different phishing and social engineering attacks, putting users at risk of data theft, wire fraud, and malware/ransomware infections.

In a new report, experts from Check Point Research detailed the flaws in the popular online collaboration platform, noting the attackers could reuse unique identifiers in the Microsoft Teams messaging system, altering the content of previously sent messages without triggering the “Edited” label.

“Sensitive conversations could be modified after the fact, eroding confidence in records and decisions,” the team warned.


You may like

Twisting the mechanics of trust

The researchers noted both mobile and desktop notifications could be manipulated to seem as if an alert was coming from a trusted executive, or colleague, which could easily be used in phishing attacks.

Furthermore, they found a way to change the displayed name in private chat conversations, by modifying the conversation topic. “Both participants see the altered topic as the conversation name, potentially misleading them about the conversation’s context.”

Finally, they found that the display name used in call notifications (and later on the call), could be modified through “specific manipulations of call initiation requests”, allowing attackers to forge caller identities.

“Attackers can twist the very trust mechanisms that make Teams effective, turning collaboration into an attack vector,” Check Point said, warning about these flaws being exploited in phishing attacks.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

To combat the threat, Microsoft first labeled the flaws as CVE-2024-38197, and rolled out a “series of fixes” which concluded in October 2025. At press time, all of the flaws have been addressed and no action from the users is required.


Best antivirus software header

The best antivirus for all budgets

Our top picks, based on real-world testing and comparisons

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Previous Post

Skip the rest – these are the best early Black Friday gaming laptop deals, plus some solid advice to save you cash

Next Post

Microsoft strengthens its in-country data processing push with more sovereignty options

Next Post
Most UK businesses don’t actually know where their data is stored

Microsoft strengthens its in-country data processing push with more sovereignty options

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

New US Senate bill calls for agencies and companies to be forced to report AI-related job cuts

by Tech Wavo
November 6, 2025
0
New US Senate bill calls for agencies and companies to be forced to report AI-related job cuts
Computers

Companies and federal agencies could have to report AI-related job lossesThere have been more federal layoffs than tech layoffs in...

Read more

NotebookLM can now test your knowledge with flashcards and quizzes

by Tech Wavo
November 6, 2025
0
NotebookLM can now test your knowledge with flashcards and quizzes
Computers

NotebookLM, the one AI tool from Google everyone loves, is about to become more useful for studying. Google has begun...

Read more

Share Your Projects: Imperfectionism | Hackaday

by Tech Wavo
November 6, 2025
0
Share Your Projects: Imperfectionism | Hackaday
Technology

Everyone has a standard for publishing projects, and they can get pretty controversial. We see a lot of people complain...

Read more

Meta brings its short-form video feed of AI slop to Europe

by Tech Wavo
November 6, 2025
0
Meta brings its short-form video feed of AI slop to Europe
Computers

Meta announced on Thursday that Vibes, its short-form video feed of AI-generated videos, is launching in Europe in the Meta...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock