惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

C
Check Point Blog
aimingoo的专栏
aimingoo的专栏
Jina AI
Jina AI
Microsoft Security Blog
Microsoft Security Blog
IT之家
IT之家
V
Visual Studio Blog
量子位
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 聂微东
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
大猫的无限游戏
大猫的无限游戏
Y
Y Combinator Blog
Stack Overflow Blog
Stack Overflow Blog
D
Docker
MyScale Blog
MyScale Blog
小众软件
小众软件
云风的 BLOG
云风的 BLOG
美团技术团队
Microsoft Azure Blog
Microsoft Azure Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Last Week in AI
Last Week in AI
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 【当耐特】

Human Risk Management Blog

Future-Proofing Organizations in the Face of AI What Security Can Learn From Dinosaurs Inside the OS-Aware Phishing Kit Profiling Your Device CyberheistNews Vol 16 #30 [Protect Your Users] AI Hallucinations Are Fueling Phishing Attacks Majority of Organizations Hit by Targeted Impersonation Attacks The Open-Source Paradox: Navigating the New Frontier of AI Supply Chain Risk Introducing The Hybrid Nudge Experience: Outbound Email Security Built for Your Risk Appetite Elevating the SOC Experience: Smarter Automation, Richer Threat Intelligence, and AI-Native Investigation New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication From Inbox to Encryption: How Ransomware Delivery Has Evolved Attackers Exploit AI Hallucinations to Send Users to Phishing Sites Warning: ARToken Phishing Kit Automates BEC Attacks The New Face of AI Risk Trust Nothing: Tips to Secure AI Tools and Agents CyberheistNews Vol 16 #29 ClickFix Social Engineering is Now the Leading Malware Delivery Method Beyond the Checkbox: How a Proactive Partnership Led to Turnkey Hazing Compliance Trust, Verify, Protect: Modernizing Email Security for the Cloud Report: Social Engineering Remains a Central Part of AI-assisted Attacks ClickFix Social Engineering is Now the Leading Malware Delivery Method CyberheistNews Vol 16 #28 Your 2026 Phishing by Industry Benchmarks: The Findings on Human Risk Scammers Can Use AI Tools to Pinpoint Your Location Based on a Photo Report: Attackers Are Using AI to Automate Social Engineering Your KnowBe4 Fresh Compliance Plus Content Updates from June 2026 From Awareness to Digital Workforce Security Your KnowBe4 Fresh Content Updates from June 2026 Threat Actor Uses Phishing to Breach Orgs for Ransomware Gangs Invoice Phishing Attacks Are Abusing the Shop App Phishing Campaign Impersonates Interpol to Deliver Ransomware Prompt Injection and the Rise of Agentic Risk Hyper-Targeted Social Engineering Needs Real-Time Video Response
Attackers aren’t loyal to any collaboration channel
Javvad Malik · 2026-06-24 · via Human Risk Management Blog

Cloud email security has become pretty good. Not perfect, obviously, because the attack landscape is forever changing. But good enough that the old tactics do not land with the same success rate they once did. Filters are sharper. Detection is better. Users are smarter.

So criminals, being criminals and not entirely stupid, look elsewhere. Attackers do not develop emotional loyalty to a channel. They are not sat there nostalgically insisting that if phishing is going to be done, it ought to be done properly and via email like in the good old days. They go where the people are, and more importantly, where the people are less guarded.

Which brings us to collaboration platforms such as Teams which look to be overtaking email as many people’s preferred method of communication. It can be quick, convenient, and to the point, without any of the “I hope this email finds you well” filler.

However, while people have been trained over the years to be cautious of emails, Teams and other similar channels have an informal trustworthy feel about them. Which is exactly what criminals are increasingly seeking to take advantage of. A Teams message just appears in a high-paced workspace they use all the time, and it feels internal … even when it’s not.

Microsoft Teams external access has made collaboration easier across organisations, which has many benefits. But in doing so, it has also created a new avenue for attackers because it expands who can reach your users and how those interactions show up.

The default setting for Teams external access allows all external domains, meaning users can chat and meet with people outside the organisation, assuming the other side also has external access enabled.

If email has become harder to exploit, the sensible thing for an attacker is to move to the place where trust is higher and defences are often less mature. It is the digital equivalent of discovering the front door now has a camera, a deadbolt, and a suspicious dog, so instead you wander round the back and try the patio doors.

The thinking though shouldn’t be restricted just to Teams, that just happens to be the current example of a much broader issue.

Security teams have historically organised themselves around channels. Email, web, endpoint, network, etc. A simple label and clear budget. But attackers don’t care about labels or budgets. They care about people, processes, workflows and moments of trust. If a finance employee is just as likely to respond to a convincing message in chat as they are in email, then from the attacker’s point of view those are not separate problems. They are simply two doors into the same house.

That means organisations need to think less in terms of protecting apps and more in terms of protecting interactions. Where are employees communicating? Which channels feel trusted? What happens when someone external appears? How easy is it for a user to verify identity, report something suspicious, or pause a conversation before doing something regrettable?

These are not just technical questions. They are questions about human behaviour, platform design, and whether we have a culture that supports people in their security journey.

The reason collaboration security matters is because work has changed. People now operate across inboxes, chats, shared docs, calls, AI assistants, and whatever other platforms appeared after somebody said they wanted to improve productivity. Trust has spread across all of them. So risk has too.

This is why the conversation needs to evolve. Not away from email security, but beyond it. If criminals are adapting to where people work, then security needs to adapt to how people work. That means visibility across channels, consistent reporting mechanisms, thoughtful configuration of external access, and user education that is relevant to them, their roles, and the threats they face.

Javvad Malik is Lead CISO Advisor at KnowBe4 and suspects most modern attack surfaces were created by people who have never had to explain an incident to a board at 7 a.m.