< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-09-24T12:02:03+05:30

TeamFiltration Exploits Default Passwords in Microsoft 365 Service Accounts

A TeamFiltration campaign exploited default passwords in Microsoft 365 service accounts, compromising seven unmanaged functional accounts across Chilean financial and retail institutions. The attack utilized the TeamFiltration framework for brute-force enumeration and exfiltration, highlighting risks from unmonitored service accounts with unrotated credentials.

Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants.

According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses.

"The campaign compromised 7 accounts –

Read original article

*** END OF TRANSMISSION ***