Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

APT29 (Cloaked Ursa) and UNC6692 are actively exploiting Microsoft Teams’ default external federation settings to impersonate IT helpdesk staff, trick employees into approving fraudulent multi-factor authentication prompts, and gain initial access to enterprise environments. The root cause is a permissive-by-default configuration present across millions of Microsoft 365 tenants, not a software vulnerability, meaning any organization that has not explicitly restricted external Teams federation is exposed today. Successful intrusions have led to privilege escalation via Microsoft Entra Privileged Identity Management, putting administrative access, sensitive data, and downstream cloud infrastructure at risk.

Author

Tech Jacks Solutions