Review Teams helpdesk impersonation with Defender XDR
Microsoft Threat Intelligence reports an active campaign in which external contacts in Microsoft Teams impersonate IT or helpdesk staff. The entry point is not a Teams vulnerability, but a trusted-looking support workflow: the user is persuaded to start or approve a remote session, after which the operator uses PowerShell to download and silently install an … Read more
