Evento di Lancio: Smart AI Security. Controllo Totale dei Dati. Prenota il tuo posto

chiudere
chiudere
La tua rete di domani
La tua rete di domani
Pianifica il tuo percorso verso una rete più veloce, sicura e resiliente, progettata per le applicazioni e gli utenti che supporti.
Experience Netskope
Prova direttamente la piattaforma Netskope
Ecco la tua occasione per sperimentare in prima persona la piattaforma single-cloud di Netskope One. Iscriviti a laboratori pratici e a ritmo autonomo, unisciti a noi per dimostrazioni mensili di prodotti dal vivo, fai un test drive gratuito di Netskope Private Access o partecipa a workshop dal vivo guidati da istruttori.
Un leader in SSE. Ora è un leader nel settore SASE a singolo fornitore.
Netskope è riconosciuto come Leader Più Lontano in Visione sia per le piattaforme SSE che SASE
2 volte leader nel Quadrante Magico di Gartner® per piattaforme SASE
Una piattaforma unificata costruita per il tuo percorso
Securing Generative AI for Dummies
Securing Generative AI for Dummies
Scopri come la tua organizzazione può bilanciare il potenziale innovativo dell'AI generativa con pratiche solide di sicurezza dei dati.
eBook sulla Modern Data Loss Prevention (DLP) for Dummies
Modern Data Loss Prevention (DLP) for Dummies
Ricevi consigli e trucchi per passare a un DLP fornito dal cloud.
Modern SD-WAN for SASE Dummies Book
Modern SD-WAN for SASE Dummies
Smettila di inseguire la tua architettura di rete
Comprendere dove risiede il rischio
Advanced Analytics trasforma il modo in cui i team di operazioni di sicurezza applicano insight basati sui dati per implementare policy migliori. Con l'Advanced Analytics, puoi identificare tendenze, concentrarti sulle aree di interesse e utilizzare i dati per agire.
Supporto tecnico Netskope
Supporto tecnico Netskope
I nostri ingegneri di supporto qualificati sono dislocati in tutto il mondo e possiedono competenze diversificate in sicurezza cloud, networking, virtualizzazione, content delivery e sviluppo software, garantendo un'assistenza tecnica tempestiva e di qualità.
Video Netskope
Formazione Netskope
La formazione Netskope ti aiuterà a diventare un esperto di sicurezza cloud. Siamo qui per aiutarti a proteggere il tuo percorso di trasformazione digitale e a sfruttare al meglio le tue applicazioni cloud, web e private.

Mitigating the Latest Microsoft Teams Vulnerability with Netskope

Jul 24 2023

Recently, a team of experts from JumpSEC Labs discovered a vulnerability in Microsoft Teams that allows malicious actors to bypass policy controls and introduce malware through external communication channels. Leaving end-users susceptible to phishing attacks. 

Microsoft’s advice is to educate end-users to detect phishing attempts. One workaround would be to disable Microsoft Teams collaboration with external organizations.

This particular vulnerability in Microsoft Teams enables threat actors to bypass existing policy controls, allowing them to share links to malicious files within Teams chats, without the end-user ever accepting a message-request. This circumvention of security measures can have severe consequences for organizations, especially considering that Microsoft Teams boasts a user base of 300 million users worldwide.

To make matters worse, this attack does not rely on email, bypassing traditional email security measures and abusing the inherent trust end-users have with collaboration tools. Besides end-users, many organizations inherently trust SaaS as a reliable source as well. This translates to security controls where trusted sources are not inspected and thus bypassed.

The Netskope Threat Labs Stats for June 2023 blog revealed that 60% of all malware downloads through HTTP/HTTPS were traced back to popular cloud apps. Additionally, 32% of SaaS-delivered malware originated from OneDrive and SharePoint, indicating the need for strengthened security measures on these platforms. The notion that SaaS is considered a ”trusted source” directly contradicts the fundamental principle of zero trust.

Based on these principles, organizations should always inspect all downloads for threats, regardless of their origin. This approach allows organizations to enable external parties to share content while still leveraging Netskope Advanced Threat Protection to block malicious file transfers.

To effectively combat such threats, organizations need a comprehensive cybersecurity solution that follows the principles of zero trust and secure access service edge (SASE). Netskope implements these principles through its private cloud platform regardless of an organization’s location or the nature of their workloads (Web, SaaS, VPC, IaaS, etc.), protecting users and machines across various environments.

The power Netskope provides is the ability to identify and control the usage of specific SaaS instances within a service. This granular control empowers organizations to mitigate and manage risks effectively while enabling collaboration across multiple SaaS platforms. By implementing Netskope, organizations can protect users from interacting with unknown and unmanaged SaaS applications, including those originating from desktop clients like Microsoft Teams. Additionally, Netskope allows organizations to enforce limitations on SaaS activities, such as sharing, liking, reposting, and downloading files, especially when they involve trusted external partners.

These capabilities make it possible to protect end-users against these phishing attacks as shown in the diagram below.

MS Teams Abuse

Additionally, to enable these security measures, Netskope leverages advanced threat protection techniques such as sandboxing and data protection. These features allow for the scanning of sensitive information, such as personally identifiable information (PII), source code, or medical records, to identify potential threats or policy violations. By combining these advanced measures with the robust Netskope security platform, organizations can effectively defend against emerging threats.

Netskope’s Advanced Analytics capabilities provide security teams with specific dashboards and valuable insights to assess the risk of rogue cloud instances being exploited for malware delivery or the potential of anomalous communications targeting the organization. Rich details and comprehensive analysis empower security teams to make informed decisions and streamline the mitigation and remediation processes. The Sankey diagram below showcases a visual representation of the interaction between various SaaS, the used instances, and their respective activities.

Netskope Advanced Analytics Dashboard to assess the risk of rogue cloud instances

The Microsoft Teams vulnerability discussed in this blog highlights the importance of comprehensive visibility, understanding, and control of SaaS, the instances, and the activities within.

By leveraging the comprehensive security solutions offered by Netskope, organizations can effectively protect themselves from emerging threats and vulnerabilities by applying zero trust, advanced threat protection and robust data security measures.

To learn more on how Netskope can help your organization to mitigate similar risks via instance awareness, watch this demo: Defending against cloud threats with instance-awareness. Additionally, to learn more about the latest emergent cloud-native threats, and how Netskope can mitigate them, subscribe to the Cloud Threats Memos so you don’t miss a threat!

author image
Mitchell Pompe
Mitchell is a cloud security professional in the Netherlands, with 10 years of experience in networking and a master's degree in cybersecurity engineering.
Mitchell is a cloud security professional in the Netherlands, with 10 years of experience in networking and a master's degree in cybersecurity engineering.
Connettiti con Netskope

Iscriviti al blog di Netskope

Iscriviti per ricevere ogni mese una panoramica degli ultimi contenuti di Netskope direttamente nella tua casella di posta.