A vishing campaign exploits Microsoft Teams for remote access extortion and leads to Chaos ransomware encryption in at least three cases within under 17 hours.
Facilitator analyzes Teams meetings in real-time and automatically answers open questions via web search in the chat without interrupting the conversation – but requires Copilot Premium and can be disabled at administrator level.
CISOs can now block external bots system-wide and automatically route them to the meeting lobby, where the organizer must grant explicit approval – with upcoming whitelist and audit features.
Keeper Security brings privileged access management directly into Microsoft Teams to centralize approval processes for sensitive access and improve auditability.
Ransomware group DragonForce disguises its command-and-control traffic via Microsoft Teams’ TURN protocol and exploits multiple CVEs and kernel exploits to bypass security software.
Microsoft is launching a WLAN-based office presence detection in Teams in June 2026 after multiple delays, which functions only with explicit administrator activation and automatically deletes location data after business hours.