Microsoft Teams Gets External Domain Anomaly Detection to Combat Social Engineering Attacks

Share
Microsoft Teams Gets External Domain Anomaly Detection to Combat Social Engineering Attacks

Microsoft is introducing the External Domains Anomalies Report for Teams, a security feature designed to help administrators identify suspicious external communications before they escalate into breaches.

The tool, scheduled for global rollout in February 2026, addresses a critical gap as threat actors increasingly exploit Teams for social engineering campaigns.

How It Works

The feature uses pattern analysis to establish baselines of normal communication behavior and flags deviations that could indicate security concerns. The system monitors three key indicators:

  • Sudden spikes in messaging volume with external parties
  • First-time communications with previously unknown domains
  • Unusual engagement patterns that deviate from established norms

When anomalies are detected, administrators receive actionable insights through a dedicated report, enabling security teams to investigate risky interactions before data exfiltration occurs.

Why It Matters

The feature arrives as ransomware groups have intensified social engineering attacks through Teams. Black Basta has been observed flooding victim inboxes with thousands of emails, then using Teams chats to pose as IT help desk staff and convince users to install remote access tools like AnyDesk.

In late October 2024, the group added targeted users to Teams chats with external users operating from newly created Entra ID tenants designed to appear as legitimate support personnel—ultimately gaining remote access to victim machines.

Availability

The External Domains Anomalies Report will roll out to standard multi-tenant environments on the web platform starting February 2026 under Microsoft 365 Roadmap ID 536572.

Organizations can enable the feature through the Teams admin center:

  1. Navigate to Notifications & alerts → Rules
  2. Select External domain anomalies
  3. Change status to Active
  4. Choose a Teams channel to receive alert notifications

This capability builds on earlier Teams security enhancements, including warnings for malicious URLs and blocking risky file types in chats.

Read more

Nx Console VS Code Extension Compromised — 2.2 Million Installs Exposed to Credential Stealer With Sigstore Supply Chain Poisoning Capability

Nx Console VS Code Extension Compromised — 2.2 Million Installs Exposed to Credential Stealer With Sigstore Supply Chain Poisoning Capability

A compromised version of the Nx Console extension — a popular VS Code plugin with over 2.2 million installations — was published to the Visual Studio Code Marketplace after an attacker leveraged stolen developer credentials to inject a multi-stage credential stealer into the official nrwl/nx GitHub repository. The malicious version

By Zero Day Wire
Pre-Stuxnet Sabotage Malware Fast16 Confirmed as Nuclear Weapons Simulation Tampering Tool Dating Back to 2005

Pre-Stuxnet Sabotage Malware Fast16 Confirmed as Nuclear Weapons Simulation Tampering Tool Dating Back to 2005

Symantec and Carbon Black have published a definitive analysis confirming that Fast16, a Lua-based malware framework first surfaced by SentinelOne weeks ago, was purpose-built to sabotage nuclear weapons testing simulations. The findings establish Fast16 as the earliest known cyber sabotage tool targeting nuclear weapons research — predating the first known version

By Zero Day Wire