Connect with us

Hi, what are you looking for?

Business

TeamsPhisher: Why your daily meeting tool might be vulnerable

Social engineering is a highly effective and profitable attack method for hackers, and as highlighted by the 2023 Verizon Data Breach report.

The number of hacks has been increasing worldwide. — © AFP/File Noel Celis
The number of hacks has been increasing worldwide. — © AFP/File Noel Celis

A member of the U.S. Navy’s red team released a tool called TeamsPhisher recently. This unwanted innovation takes advantage of an unresolved security problem in Microsoft Teams. The vulnerability allows Teams accounts from an outside body to bypass client-side security controls and release malicious payloads directly towards the target’s inbox.

To shed more light on this incident, George Prichici, VP of Products at OPSWAT, a global leader in critical infrastructure protection (CIP) cybersecurity solutions, explains to Digital Journal about the resultant cybersecurity ramifications.

Prichici observes: “The recent news of a new tool exploiting a vulnerability in Microsoft Teams to send malware to users highlights the increasing risks associated with popular communication platforms. With a large user base and sensitive information being shared, Microsoft Teams has become an attractive target for hackers.”

In terms of the specific software application, Prichici interprets this as: “TeamsPhisher capitalizes on an already known vulnerability, allowing hackers to exploit it and send harmful files or programs to unsuspecting users. This poses a significant threat as it can lead to compromised computers and unauthorized access to sensitive information.”

The computer giant behind Teams has responded,. Says Prichici: “While Microsoft has acknowledged the issue, stating that social engineering plays a role in the success of these attacks, the human element remains a weak link.”

In terms of this weakness: “Social engineering is a highly effective and profitable attack method for hackers, and as highlighted by the 2023 Verizon Data Breach report, 74 percent of breaches involve the human element. This underscores the importance of educating employees and fostering a culture of cybersecurity awareness within organizations. However, education alone is not enough and relying on human behaviour is not fool proof.”

There are measures that can (and need) to be taken to address this and related vulnerabilities. These are set out by Prichici as: “To mitigate the risks posed by this vulnerability, organizations should adopt a proactive, layered defence approach. This includes implementing the right detection and prevention technologies like ‘Multiscanning’ (simultaneous scans with multiple AV engines), CDR (Content Disarm and Reconstruction), Vulnerability Assessment and more in automated workflows to safeguard users and prevent malware infiltration.”

In terms of other measures, Prichici continues: “Additionally, they should ensure up-to-date security software is in place to detect and block any potential malware transmitted via files shared through Microsoft Teams, as well as prioritize data storage security by scanning and sanitizing files and content for malware, redacting sensitive information, and implementing periodic scans can help mitigate the risk of malware infiltration.”

In concluding, Prichici states: “By following these measures, organizations can establish a zero-trust environment that enforces security at every step to mitigate the potential damage caused by this vulnerability.”

Where are the most successful new businesses opening in the UK?

A new study from CMC Markets has revealed which U.K. cities are home to the most successful new businesses. The data sets is indicative that the U.K. is slowly picking up its economic base. The availability of candidates for new jobs rose in June at the sharpest rate since December 2020.

The data from the study revealed Reading has the lowest percentage of closures, with just 0.13 percent of businesses launched between Dec 17-Dec 2022 going into liquidation. Stoke-on-Trent, Plymouth, and Cardiff make the top five, with less than 1 percent of new businesses ceasing in the last five years.

The research used business intelligence software, Endole, to analyse how many businesses were incorporated in the UK’s largest 25 cities from December 2017 to December 2022 compared to the number that went into administration, liquidation, or were dissolved.

Alongside Reading, Stoke-on-Trent, Plymouth, and Cardiff are also home to some of the UK’s most thriving businesses and entrepreneurs.

The top ten shows:

CityNo. of Reported OpeningsNo. of Reported ClosuresPercent of Closures
Reading6,87790.13%
Stoke-on-Trent6,228130.21%
Plymouth4,744130.27%
Cardiff18,232580.32%
Edinburgh17,372710.41%
Bradford2,655110.45%
Bristol17,043940.55%
Northampton8,993490.55%
Derby8,109450.56%
Belfast7,819620.79%

In contrast, the 10 cities with the least successful new businesses are:

CityNo. of Reported OpeningsNo. of Reported ClosuresPercent of Closures
Southampton5,3371623.04%
Sheffield13,2413973.00%
Birmingham16,3303332.04%
Leeds15,3772761.80%
Manchester35,5256221.75%
London23,1923201.38%
Coventry12,9001761.36%
Newcastle upon Tyne7,988961.20%
Kingston upon Hull6,036621.03%
Nottingham9,863950.96%

The data reveals Southampton is the city with the highest number of closures in comparison to openings between Dec 17 and Dec 2022, with 162 of these businesses ceasing trading.

Sheffield is next with 3 percent of closures, followed by Birmingham (2.04 percent) and Leeds (1.80 percent).

The City of London is also, surprisingly, amongst the areas with the least successful new businesses, seeing 1.38 percent of closures.

Avatar photo
Written By

Dr. Tim Sandle is Digital Journal's Editor-at-Large for science news. Tim specializes in science, technology, environmental, business, and health journalism. He is additionally a practising microbiologist; and an author. He is also interested in history, politics and current affairs.

You may also like:

Entertainment

Academy Award winner Colin Firth ("The King's Speech") chatted about starring in the new limited series "Lockerbie: A Search for Truth," which will premiere...

Business

“Quantum technologies are the next revolution in technology.”

Business

Operational simplicity remains key for organizations to detect Salt Typhoon activity.

Entertainment

Alexa PenaVega ("Spy Kids") chatted about her new Great American Family holiday movie, "Get Him Back for Christmas," which will premiere on Saturday, December...