Cybersecurity News in Asia

RECENT STORIES:

SEGA moves faster with flow-based network monitoring
Cybercriminals zero In on APAC’s digital boom, SMBs in the crosshairs...
And we all thought the AI agent swarm attack was just a one-off…
SU Group Secures Exclusive Distribution Rights for Portable X-Ray Syst...
SU Group Holdings Limited Announces Proposed Acquisition of KM Safety ...
AI an existential risk – and what to do about it today
LOGIN REGISTER
CybersecAsia
  • Features
    • Featured

      The recovery-first approach to data resilience

      The recovery-first approach to data resilience

      Monday, September 7, 2026, 4:21 PM Asia/Singapore | Features
    • Featured

      Dealing with agentic AI governance and resilience challenges

      Dealing with agentic AI governance and resilience challenges

      Tuesday, September 1, 2026, 11:51 AM Asia/Singapore | Features
    • Featured

      How well do you know your agent?

      How well do you know your agent?

      Thursday, August 20, 2026, 3:21 PM Asia/Singapore | Features
  • Opinions
  • Tips
  • Whitepapers
  • AWARDS 2026
  • Directory
  • E-Learning

Select Page

News

Beware of new phishing attack vector coming your way

By CybersecAsia editors | Tuesday, November 11, 2025, 8:30 AM Asia/Singapore

Beware of new phishing attack vector coming your way

Anyone could soon target you for a chat session, using a new feature enabled by default in a popular collaboration tool.

While the world tries to plug every loophole and risk that could expose people to phishing attacks, one software giant is toying with just the opposite.

In a feature expected to roll out starting November 2025, users of Microsoft Teams will be able to initiate chats with anyone just by supplying an email address, without requiring the recipient to be a Teams user.

This update, aimed at enhancing seamless collaboration across platforms such as Android, desktop, iOS, Linux, and Mac, allows external guest users to join conversations via email invites under Microsoft Entra B2B Guest policies. While it aims to improve flexibility in communication, cybersecurity experts have raised alarms about significant security risks associated with the default-enabled setting.

The primary concern is the increased attack surface:

  • By allowing external email-based chat initiations without prior validation or vetting, the feature opens avenues for phishing attacks and malware distribution. Malicious actors could send spoofed chat invites posing as trusted contacts or business partners, tricking employees into clicking harmful links, sharing credentials, or unknowingly exposing proprietary information.
  • This vector is likened to OAuth phishing campaigns, which rely heavily on impersonation to harvest sensitive data. The risks are compounded because file exchanges within Teams may bypass traditional email security filters, raising the threat of ransomware or spyware infiltrations.
  • Microsoft advises organizations to update internal policies and train staff on the new functionality. Administrators can mitigate risks by disabling the feature through PowerShell, using the TeamsMessagingPolicy attribute ‘UseB2BInvitesToAddExternalUsers’ set to false, thus restricting chats to vetted external users only.

Experts recommend additional security measures such as enforcing multi-factor authentication, conducting regular audits, and running comprehensive phishing awareness training.

Overall, while the new Teams feature offers improved external communication capabilities, the illogical choice to enable it by default will place the onus of security and privacy vigilance on users.

Share:

PreviousAPAC Threat Intelligence Latest Insights: 79% of Enterprises to Increase Investment in Threat Intelligence
NextSep–Nov 2025 data breaches in review: Prevention and proactive-ness are key

Related Posts

Is the “spiral of more” causing security operations teams to be less effective?

Is the “spiral of more” causing security operations teams to be less effective?

Monday, July 24, 2023

Beware: DeFi and crypto scammers are out to get you

Beware: DeFi and crypto scammers are out to get you

Friday, January 28, 2022

Indonesian transport firm puts cybersecurity first as it pivots to digital

Indonesian transport firm puts cybersecurity first as it pivots to digital

Wednesday, March 23, 2022

Tech irony: a smart tracking device for the vulnerable actually endangered them

Tech irony: a smart tracking device for the vulnerable actually endangered them

Wednesday, July 15, 2020

Leave a reply Cancel reply

You must be logged in to post a comment.

Voters-draw/RCA-Sponsors

Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
previous arrow
next arrow

CybersecAsia Voting Placement

Gamification listing or Participate Now

PARTICIPATE NOW

Vote Now -Placement(Google Ads)

Top-Sidebar-banner

Whitepapers

  • Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Cyber threats have become more frequent and sophisticated, targeting organizations of all sizes across all …Download Whitepaper
  • Zero Trust Made Simple: Why it matters and how to get started

    Zero Trust Made Simple: Why it matters and how to get started

    Data breaches and cyberattacks are no longer limited to large, high-profile organizations.Download Whitepaper
  • Cloud Secure Edge: Remote access, better security

    Cloud Secure Edge: Remote access, better security

    ​SonicWall Cloud Secure Edge™ is a modern, cloud-native Security Service Edge (SSE) solution that addresses …Download Whitepaper
  • Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper

Middle-sidebar-banner

Case Studies

  • How a Vietnamese D2C retailer built its own secure digital infrastructure

    How a Vietnamese D2C retailer built its own secure digital infrastructure

    Would your organization build your own digital infrastructure – including AI governance and cybersecurity – …Read more
  • Cyber protection for medical clinics in Singapore

    Cyber protection for medical clinics in Singapore

    As Singapore’s healthcare sector becomes increasingly digital and interconnected, clinics are facing heightened cyber risks, …Read more
  • India’s WazirX strengthens governance and digital asset security

    India’s WazirX strengthens governance and digital asset security

    Revamping its custody infrastructure using multi‑party computation tools has improved operational resilience and institutional‑grade safeguardsRead more
  • Bangladesh LGED modernizes communication while addressing data security concerns

    Bangladesh LGED modernizes communication while addressing data security concerns

    To meet emerging data localization/privacy regulations, the government engineering agency deploys a secure, unified digital …Read more

Bottom sidebar

Other News

  • SU Group Secures Exclusive Distribution Rights for Portable X-Ray System in Hong Kong and Macau

    Tuesday, September 15, 2026
    Second International Distribution Deal of …Read More »
  • SU Group Holdings Limited Announces Proposed Acquisition of KM Safety Solution Company Limited

    Tuesday, September 15, 2026
    HONG KONG, Sept. 15, 2026 …Read More »
  • Fujitsu launches made-in-Japan next-generation CPU FUJITSU-MONAKA and Fujitsu MONAKA Server for sovereign AI infrastructure

    Monday, September 14, 2026
    Achieving world-class AI inference performance …Read More »
  • Aitech Introduces New C165 Rugged Single Board Computer to Help Defense Programs Build and Modernize Fielded VME Systems

    Monday, September 14, 2026
    New 6U VME SBC Delivers …Read More »
  • CyberDSA 2026 Draws Global Cyber Leaders for High-Level Talks on AI, Digital Trust and Critical Infrastructure

    Friday, September 11, 2026
    Minister of Digital Malaysia YB …Read More »
  • Our Brands
  • DigiconAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 CybersecAsia All Rights Reserved.