Microsoft Defender for Office 365: Post-delivery protection for malicious QR codes in Microsoft Teams
🚨 The Signal: Microsoft Defender for Office 365 now detects malicious URLs in QR codes within Teams messages post-delivery. This enhances protection against QR code phishing and improves threat visibility for security operations.
The Impact
Organizations using Defender for Office 365 and Teams are affected, reducing the risk of successful QR code phishing attacks.
- Teams users: Reduced risk from malicious QR codes.
- Security operations: Enhanced visibility into QR code threats.
- Defender for O365 admins: Improved post-delivery protection.
- Advanced Hunting users: New data for threat investigations.
The Action
- Review existing Microsoft Defender for Office 365 policies for Teams URL protection.
- Familiarize security operations teams with the MessageUrlInfo table in Advanced Hunting for QR code detections.
- Ensure Zero-hour Auto Purge (ZAP) for Teams is enabled for maximum protection against internal messages.
Domain: Defender · Impact: high · Workload: Microsoft Defender