Close Menu
TechUpdateAlert

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I Didn’t Know This 5-Minute Bedtime Task Would Help Me Sleep Better

    August 8, 2025

    21 Best Festival Accessories and Gear (2025): The Essentials and the Fun Stuff

    August 8, 2025

    Panasonic ShinobiPro MiniLED TVs Launched in India Alongside New 2025 P-Series Models

    August 8, 2025
    Facebook X (Twitter) Instagram
    Trending
    • I Didn’t Know This 5-Minute Bedtime Task Would Help Me Sleep Better
    • 21 Best Festival Accessories and Gear (2025): The Essentials and the Fun Stuff
    • Panasonic ShinobiPro MiniLED TVs Launched in India Alongside New 2025 P-Series Models
    • Ready or Not Regains Flagship Xbox Feature, Play Anywhere
    • Here’s how I stop spam emails from ever reaching my inbox
    • Breath Work, Biohacking, and Cryotherapy: New Buzzwords for Modern Business Travelers
    • Apple Must Allow Alternative Browser Engines on iOS by December Under Japan’s New Mobile Software Competition Act
    • Samsung Galaxy Buds 3 Series Update Adds Google Gemini Support on Phones Running One UI 8
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechUpdateAlertTechUpdateAlert
    • Home
    • Gaming
    • Laptops
    • Mobile
    • Software
    • Reviews
    • AI & Tech
    • Gadgets
    • How-To
    TechUpdateAlert
    Home»Software»Microsoft Teams and Zoom can be hijacked to give hackers the keys to your kingdom
    Software

    Microsoft Teams and Zoom can be hijacked to give hackers the keys to your kingdom

    techupdateadminBy techupdateadminAugust 7, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Microsoft Teams on an iPhone
    Share
    Facebook Twitter LinkedIn Pinterest Email


    • Experts say Microsoft Teams and Zoom are perfect for hiding Ghost Calls
    • Attackers can obtain temporary TURN credentials and create a tunnel
    • Vendors must implement safeguards, because there are no vulnerabilities in sight

    Researchers from Praetorian have shed the light on Ghost Calls, a post-exploitation command-and-control evasion technique which send attacker traffic through legitimate Traversal Using Relays around NAT (TURN) servers used by the likes of Zoom and Microsoft Teams, to evade detection.

    The attack works by hijacking the temporary TURN credentials that conferencing calls receive when they join a meeting, and then establishing a tunnel between the compromised host and the attacker’s machine.

    Because all the traffic is routed through trusted Zoom/Teams IPs and domains, which are typically whitelisted inside enterprises, these types of hijacking attacks can fly under the radar.


    You may like

    Teams and Zoom susceptible to attacks

    Praetorian explained that because the attack leverages infrastructure already allowed through corporate firewall,s proxies and TLS inspection, Ghost Calls can easily evade traditional defenses.

    Blending traffic with normal, low-latency video meeting traffic patterns also helps the cybercriminals, who can eliminate the exposure of attacker-controlled domains and servers

    Praetorian explains in the first of its two blog posts that video conferencing platforms “are designed to function even in environments with relatively strict egress controls,” so if an attacker can crack into these systems, they could have a higher chance of data exfiltration.

    “Additionally, this traffic is often end-to-end encrypted using AES or other strong encryption. This means the traffic is naturally heavily obfuscated and impossible to analyze in depth which makes it a perfect place to hide as an attacker,” the researchers added.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    TURN credentials typically expire after two to three days, so tunnels are short-lived, but alarmingly, Praetorian explains that there isn’t necessarily a vulnerability for vendors to patch, adding that they must instead focus on introducing further safeguards to prevent against Ghost Call attacks.

    You might also like

    give Hackers hijacked keys kingdom Microsoft Teams Zoom
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleIs Your Fan in the Right Spot? Move It Here to Beat the Heat
    Next Article Greenland’s Melting Glaciers Feed Ocean Life, Study Finds
    techupdateadmin
    • Website

    Related Posts

    Software

    Breath Work, Biohacking, and Cryotherapy: New Buzzwords for Modern Business Travelers

    August 8, 2025
    Software

    Herman Miller’s surprise sale slashes prices by 25% – and these are the office chair deals I’d buy for your home and office

    August 8, 2025
    Software

    iOS 26: Friends Can’t Decide What to Eat? Here’s How to Create a Poll in Messages

    August 8, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Apple Pencil With ‘Trackball’ Tip, Ability to Draw on Any Surface Described in Patent Document

    July 9, 20253 Views

    Samsung Galaxy Z Fold 7 and Galaxy Z Flip 7: First Impressions

    July 9, 20253 Views

    The Bezos-funded climate satellite is lost in space

    July 9, 20252 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Best Fitbit fitness trackers and watches in 2025

    July 9, 20250 Views

    There are still 200+ Prime Day 2025 deals you can get

    July 9, 20250 Views

    The best earbuds we’ve tested for 2025

    July 9, 20250 Views
    Our Picks

    I Didn’t Know This 5-Minute Bedtime Task Would Help Me Sleep Better

    August 8, 2025

    21 Best Festival Accessories and Gear (2025): The Essentials and the Fun Stuff

    August 8, 2025

    Panasonic ShinobiPro MiniLED TVs Launched in India Alongside New 2025 P-Series Models

    August 8, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    © 2025 techupdatealert. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.