<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Microsoft Teams</title><description>Cybersecurity articles tagged #Microsoft Teams on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Microsoft Teams Abuse, The Gentlemen Ransomware, and PhaaS Trends</title><link>https://runtimerebel.com/blog/microsoft-teams-abuse-the-gentlemen-ransomware-and-phaas-trends</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-teams-abuse-the-gentlemen-ransomware-and-phaas-trends</guid><description>Analysis of social engineering campaigns via Microsoft Teams, The Gentlemen ransomware operations, and emerging phishing-as-a-service kits.</description><pubDate>Fri, 04 Sep 2026 02:00:26 GMT</pubDate><category>Microsoft Teams</category><category>Ransomware</category><category>Phishing</category><category>Credential Theft</category><category>RMM</category></item><item><title>Spring Ring Voice Phishing Targets Microsoft Teams Users</title><link>https://runtimerebel.com/blog/spring-ring-voice-phishing-targets-microsoft-teams-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/spring-ring-voice-phishing-targets-microsoft-teams-users</guid><description>Spring Ring is an ongoing vishing campaign leveraging external Microsoft Teams accounts to impersonate IT support for payload delivery and NTLM relay attacks.</description><pubDate>Tue, 01 Sep 2026 02:47:23 GMT</pubDate><category>Microsoft Teams</category><category>Vishing</category><category>Social Engineering</category><category>NTLM Relay</category><category>Spring Ring</category></item><item><title>SynkLoader Malware Steals Credentials in Microsoft Teams Phishing</title><link>https://runtimerebel.com/blog/synkloader-malware-steals-credentials-in-microsoft-teams-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/synkloader-malware-steals-credentials-in-microsoft-teams-phishing</guid><description>New SynkLoader malware distributed via Microsoft Teams phishing campaigns uses a fake lock screen to steal Windows credentials, enabling corporate network access.</description><pubDate>Sat, 22 Aug 2026 00:40:08 GMT</pubDate><category>Malware</category><category>Phishing</category><category>Microsoft Teams</category><category>Credential Theft</category><category>Ransomware</category></item><item><title>EtherRAT Malware via Microsoft Teams IT Support Impersonation</title><link>https://runtimerebel.com/blog/etherrat-malware-via-microsoft-teams-it-support-impersonation</link><guid isPermaLink="true">https://runtimerebel.com/blog/etherrat-malware-via-microsoft-teams-it-support-impersonation</guid><description>Threat actors leverage fake IT support calls on Microsoft Teams to deploy EtherRAT malware, gaining initial access to corporate networks.</description><pubDate>Mon, 06 Jul 2026 21:39:59 GMT</pubDate><category>EtherRAT</category><category>Microsoft Teams</category><category>Social Engineering</category><category>Impersonation</category><category>Initial Access</category><category>Malware</category></item><item><title>Microsoft Teams: New Controls for AI Bot Meeting Access</title><link>https://runtimerebel.com/blog/microsoft-teams-new-controls-for-ai-bot-meeting-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-teams-new-controls-for-ai-bot-meeting-access</guid><description>Microsoft Teams introduces new admin policies requiring organizer approval for external AI bots, enhancing control over automated participants in sensitive meetings.</description><pubDate>Thu, 02 Jul 2026 07:37:17 GMT</pubDate><category>Microsoft Teams</category><category>AI Bots</category><category>Meeting Security</category><category>Access Control</category><category>Cloud Security</category></item><item><title>Microsoft Teams Enhances Meeting Security with New Bot Protection Policy</title><link>https://runtimerebel.com/blog/microsoft-teams-enhances-meeting-security-with-new-bot-protection-policy</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-teams-enhances-meeting-security-with-new-bot-protection-policy</guid><description>Microsoft introduces a new admin policy for Teams meetings, preventing unapproved third-party bots from joining, mitigating meeting bombing incidents.</description><pubDate>Tue, 30 Jun 2026 12:50:08 GMT</pubDate><category>Microsoft Teams</category><category>Bot Protection</category><category>Meeting Security</category><category>Admin Policy</category><category>Cloud Security</category></item><item><title>KongTuke Exploits Microsoft Teams for Rapid Corporate Breaches</title><link>https://runtimerebel.com/blog/kongtuke-exploits-microsoft-teams-for-rapid-corporate-breaches</link><guid isPermaLink="true">https://runtimerebel.com/blog/kongtuke-exploits-microsoft-teams-for-rapid-corporate-breaches</guid><description>Initial access broker KongTuke leverages Microsoft Teams to deploy DarkGate malware, achieving network persistence in under five minutes via social engineering.</description><pubDate>Thu, 14 May 2026 12:45:59 GMT</pubDate><category>KongTuke</category><category>Microsoft Teams</category><category>DarkGate</category><category>Initial Access</category><category>Storm 0324</category></item><item><title>MuddyWater Exploits Microsoft Teams via Chaos Ransomware Decoy</title><link>https://runtimerebel.com/blog/muddywater-exploits-microsoft-teams-via-chaos-ransomware-decoy</link><guid isPermaLink="true">https://runtimerebel.com/blog/muddywater-exploits-microsoft-teams-via-chaos-ransomware-decoy</guid><description>Iranian APT MuddyWater utilizes Microsoft Teams social engineering and Chaos ransomware decoys to mask state-sponsored espionage operations.</description><pubDate>Wed, 06 May 2026 16:40:16 GMT</pubDate><category>MuddyWater</category><category>Chaos Ransomware</category><category>Microsoft Teams</category><category>Social Engineering</category><category>MOIS</category></item><item><title>MuddyWater Exploits Microsoft Teams for False Flag Ransomware</title><link>https://runtimerebel.com/blog/muddywater-exploits-microsoft-teams-for-false-flag-ransomware</link><guid isPermaLink="true">https://runtimerebel.com/blog/muddywater-exploits-microsoft-teams-for-false-flag-ransomware</guid><description>Iranian APT MuddyWater is leveraging Microsoft Teams social engineering to deploy false flag ransomware, obscuring state-sponsored espionage activities.</description><pubDate>Wed, 06 May 2026 16:38:58 GMT</pubDate><category>MuddyWater</category><category>Microsoft Teams</category><category>Ransomware</category><category>APT</category><category>Social Engineering</category></item><item><title>Microsoft Teams Free Backend Change Disrupts Chat and Calling</title><link>https://runtimerebel.com/blog/microsoft-teams-free-backend-change-disrupts-chat-and-calling</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-teams-free-backend-change-disrupts-chat-and-calling</guid><description>Microsoft confirms a backend configuration change has broken core functionality for Microsoft Teams Free users, impacting global business communication.</description><pubDate>Wed, 29 Apr 2026 08:53:02 GMT</pubDate><category>Microsoft Teams</category><category>SaaS Outage</category><category>Cloud Availability</category><category>Microsoft 365</category><category>Business Continuity</category></item><item><title>UNC6692 Leverages Teams, AWS S3 for Malware &amp; Cloud Abuse</title><link>https://runtimerebel.com/blog/unc6692-leverages-teams-aws-s3-for-malware-cloud-abuse</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc6692-leverages-teams-aws-s3-for-malware-cloud-abuse</guid><description>Newly discovered threat actor UNC6692 combines social engineering via Microsoft Teams with custom &apos;Snow&apos; malware and AWS S3 cloud abuse in multi-pronged attacks.</description><pubDate>Mon, 27 Apr 2026 20:30:32 GMT</pubDate><category>UNC6692</category><category>Microsoft Teams</category><category>AWS S3</category><category>SNOW Malware</category><category>Social Engineering</category><category>Cloud Abuse</category><category>Threat Actor</category></item><item><title>UNC6692 Targets Microsoft Teams to Deploy Snow Malware</title><link>https://runtimerebel.com/blog/unc6692-targets-microsoft-teams-to-deploy-snow-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc6692-targets-microsoft-teams-to-deploy-snow-malware</guid><description>UNC6692 is leveraging Microsoft Teams and social engineering to deliver the modular Snow malware suite, facilitating long-term persistence and data theft.</description><pubDate>Sat, 25 Apr 2026 16:17:06 GMT</pubDate><category>UNC6692</category><category>Microsoft Teams</category><category>SNOW Malware</category><category>Social Engineering</category><category>Backdoor</category><category>Persistence</category></item><item><title>UNC6692 Social Engineering: Deploying the SNOW Custom Malware Suite</title><link>https://runtimerebel.com/blog/unc6692-social-engineering-deploying-the-snow-custom-malware-suite</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc6692-social-engineering-deploying-the-snow-custom-malware-suite</guid><description>UNC6692 leverages Microsoft Teams and S3-hosted payloads to deploy the SNOW modular malware ecosystem, targeting enterprise Windows environments.</description><pubDate>Fri, 24 Apr 2026 08:51:05 GMT</pubDate><category>UNC6692</category><category>SNOWBELT</category><category>SNOWGLAZE</category><category>SNOWBASIN</category><category>Microsoft Teams</category><category>Social Engineering</category></item><item><title>UNC6692 Impersonates IT Helpdesk to Deploy SNOW Malware via Teams</title><link>https://runtimerebel.com/blog/unc6692-impersonates-it-helpdesk-to-deploy-snow-malware-via-teams</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc6692-impersonates-it-helpdesk-to-deploy-snow-malware-via-teams</guid><description>UNC6692 threat actors are impersonating IT helpdesk staff via Microsoft Teams to deliver custom SNOW malware, highlighting risks in SaaS messaging apps.</description><pubDate>Thu, 23 Apr 2026 20:25:10 GMT</pubDate><category>UNC6692</category><category>Microsoft Teams</category><category>SNOW Malware</category><category>Social Engineering</category></item><item><title>Microsoft Teams Efficiency Mode: Optimizing Resource Usage for PCs</title><link>https://runtimerebel.com/blog/microsoft-teams-efficiency-mode-optimizing-resource-usage-for-pcs</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-teams-efficiency-mode-optimizing-resource-usage-for-pcs</guid><description>Microsoft introduces Efficiency Mode for Teams to reduce CPU and memory consumption on resource-constrained devices, improving overall system responsiveness.</description><pubDate>Wed, 22 Apr 2026 12:31:39 GMT</pubDate><category>Microsoft Teams</category><category>Windows 11</category><category>Performance Optimization</category><category>Endpoint Security</category></item><item><title>Microsoft Teams Abused in Helpdesk Impersonation Attacks: TTPs &amp; Mitigations</title><link>https://runtimerebel.com/blog/microsoft-teams-abused-in-helpdesk-impersonation-attacks-ttps-mitigations</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-teams-abused-in-helpdesk-impersonation-attacks-ttps-mitigations</guid><description>Microsoft warns of helpdesk impersonation attacks via Teams external collaboration.</description><pubDate>Mon, 20 Apr 2026 16:32:32 GMT</pubDate><category>Microsoft Teams</category><category>Impersonation</category><category>Social Engineering</category><category>Helpdesk</category><category>Phishing</category><category>Identity Access</category><category>Microsoft 365</category><category>External Collaboration</category></item><item><title>Edge Update Breaks Microsoft Teams Right-Click Paste Functionality</title><link>https://runtimerebel.com/blog/edge-update-breaks-microsoft-teams-right-click-paste-functionality</link><guid isPermaLink="true">https://runtimerebel.com/blog/edge-update-breaks-microsoft-teams-right-click-paste-functionality</guid><description>A recent Microsoft Edge browser update has disabled the right-click paste feature in the Microsoft Teams desktop client, impacting global user productivity.</description><pubDate>Sat, 18 Apr 2026 16:15:55 GMT</pubDate><category>Microsoft Teams</category><category>Microsoft Edge</category><category>Clipboard Bug</category><category>Webview2</category><category>Productivity Loss</category></item><item><title>KB5085516 Emergency Update: Fix for Microsoft Account Sign-in Failures</title><link>https://runtimerebel.com/blog/kb5085516-emergency-update-fix-for-microsoft-account-sign-in-failures</link><guid isPermaLink="true">https://runtimerebel.com/blog/kb5085516-emergency-update-fix-for-microsoft-account-sign-in-failures</guid><description>Microsoft releases emergency KB5085516 update to resolve widespread authentication failures affecting OneDrive, Teams, and other cloud-integrated services.</description><pubDate>Mon, 23 Mar 2026 08:25:36 GMT</pubDate><category>KB5085516</category><category>Microsoft Account</category><category>Authentication Error</category><category>Windows Update</category><category>Identity Management</category><category>Microsoft Teams</category></item><item><title>KB5079473 Update Breaks Microsoft Account Sign-ins on Windows 11</title><link>https://runtimerebel.com/blog/kb5079473-update-breaks-microsoft-account-sign-ins-on-windows-11</link><guid isPermaLink="true">https://runtimerebel.com/blog/kb5079473-update-breaks-microsoft-account-sign-ins-on-windows-11</guid><description>Microsoft confirms the KB5079473 March update for Windows 11 disrupts sign-ins for Teams and OneDrive. Technical analysis and remediation for affected systems.</description><pubDate>Fri, 20 Mar 2026 08:18:16 GMT</pubDate><category>KB5079473</category><category>Windows 11</category><category>Microsoft Teams</category><category>Authentication</category><category>OneDrive</category></item><item><title>Microsoft Teams Phishing Deploys A0Backdoor via Quick Assist</title><link>https://runtimerebel.com/blog/microsoft-teams-phishing-deploys-a0backdoor-via-quick-assist</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-teams-phishing-deploys-a0backdoor-via-quick-assist</guid><description>Attackers are targeting healthcare and finance employees with Microsoft Teams phishing to deploy A0Backdoor using the native Windows Quick Assist tool.</description><pubDate>Tue, 10 Mar 2026 00:31:34 GMT</pubDate><category>Microsoft Teams</category><category>A0Backdoor</category><category>Quick Assist</category><category>Social Engineering</category><category>Healthcare</category><category>Financial Services</category></item><item><title>Microsoft Teams Third-Party Bot Tagging Enhances Meeting Security</title><link>https://runtimerebel.com/blog/microsoft-teams-third-party-bot-tagging-enhances-meeting-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-teams-third-party-bot-tagging-enhances-meeting-security</guid><description>Microsoft Teams updates meeting lobbies to identify third-party bots, helping administrators prevent unauthorized data collection and social engineering.</description><pubDate>Mon, 09 Mar 2026 20:12:50 GMT</pubDate><category>Microsoft Teams</category><category>Meeting Security</category><category>Third Party Bots</category><category>Social Engineering</category><category>Data Privacy</category></item></channel></rss>