TWINLOOT Exploits SharePoint, Teams for Credential Theft

TL;DR. A new attack method, dubbed TWINLOOT, abuses Microsoft SharePoint and Teams to steal credentials and navigate networks. - The technique exploits identity exposure to establish active attack paths within cloud environments. - Attackers use valid credentials to bypass traditional security controls and access sensitive data. - This method highlights vulnerabilities in commonly used enterprise collaboration platforms.

Sources

Back to QLANKR News