WashingtonWeeklyTimes.com
  • Home
  • US News
    The little-known Medicare surtax may hammer millions in Obamacare tax battle

    The little-known Medicare surtax may hammer millions in Obamacare tax battle

    Arkansas man arrested for allegedly threatening Walmart mass shooting

    Arkansas man arrested for allegedly threatening Walmart mass shooting

    Lindsey Graham warns Republicans who ‘try to destroy’ Trump will lose

    Lindsey Graham warns Republicans who ‘try to destroy’ Trump will lose

    Selfie video captures scary moment baseball fan at Mariners game gets hit in the skull by foul ball

    Selfie video captures scary moment baseball fan at Mariners game gets hit in the skull by foul ball

    401(k) account takeover fraud drained 1,430 in a single phone call

    401(k) account takeover fraud drained $751,430 in a single phone call

  • Politics
    A Planned Democratic Investigation Is The First Step In Trump Family Corruption Charges

    A Planned Democratic Investigation Is The First Step In Trump Family Corruption Charges

    Pete Buttigieg Totally Wrecks Trump Transportation Secretary Sean Duffy

    Pete Buttigieg Totally Wrecks Trump Transportation Secretary Sean Duffy

    The Iran War Has Broken Trump

    The Iran War Has Broken Trump

    Trump Doesn’t Have Enough Votes To Get His Ballroom Money

    Trump Doesn’t Have Enough Votes To Get His Ballroom Money

  • Business
    Anaplan CEO: AI isn’t eating software. It’s sorting it

    Anaplan CEO: AI isn’t eating software. It’s sorting it

    World Economic Forum: women’s health gets only 20% of R&D funding. We must seize this  trillion opportunity

    World Economic Forum: women’s health gets only 20% of R&D funding. We must seize this $1 trillion opportunity

    CDC to escalate Ebola response after WHO declares emergency

    CDC to escalate Ebola response after WHO declares emergency

    The top foreign holders of US debt may soon dump Treasury bonds and bring their money back home

    The top foreign holders of US debt may soon dump Treasury bonds and bring their money back home

  • Science
    Finnish Researchers Print Bone-Like Scaffolds That Let the Body Do the Rest

    Finnish Researchers Print Bone-Like Scaffolds That Let the Body Do the Rest

    Did Homo erectus and Denisovans mate? Tooth proteins hint at ancient trysts

    Did Homo erectus and Denisovans mate? Tooth proteins hint at ancient trysts

    SpaceX is about to launch tallest and most powerful rocket in history

    SpaceX is about to launch tallest and most powerful rocket in history

    The First Atomic Bomb Test in 1945 Created an Entirely New Material

    The First Atomic Bomb Test in 1945 Created an Entirely New Material

  • Technology
    South Korea’s LetinAR is building optics behind AI glasses

    South Korea’s LetinAR is building optics behind AI glasses

    The 6 Best Grills and Smokers of 2026: Smart, Portable, Pellet

    The 6 Best Grills and Smokers of 2026: Smart, Portable, Pellet

    Apple’s Siri revamp could include auto-deleting chats

    Apple’s Siri revamp could include auto-deleting chats

    Oto Smart Sprinkler Review (2026): Solar-Powered and Simple to Use

    Oto Smart Sprinkler Review (2026): Solar-Powered and Simple to Use

  • Lifestyle
    Spring Nourishment Rituals That Will Change the Way You Eat

    Spring Nourishment Rituals That Will Change the Way You Eat

    27 Easy Dishes for Your BBQ

    27 Easy Dishes for Your BBQ

    5 Summer Hosting Outfit Formulas That Make Getting Dressed Easy

    5 Summer Hosting Outfit Formulas That Make Getting Dressed Easy

    13 Healthy Summer Cookbooks for Light, Seasonal Cooking

    13 Healthy Summer Cookbooks for Light, Seasonal Cooking

  • Music
    Avohee Avoher Ignites the Night with the Electrifying “Malami”

    Avohee Avoher Ignites the Night with the Electrifying “Malami”

    The Smashing Pumpkins Announce the Rats in a Cage Tour

    The Smashing Pumpkins Announce the Rats in a Cage Tour

    Every 2026 ACMs Performance, Ranked

    Every 2026 ACMs Performance, Ranked

    Watch Will Ferrell’s ‘SNL’ monologue get hijacked by doppelgänger Chad Smith of Red Hot Chili Peppers

    Watch Will Ferrell’s ‘SNL’ monologue get hijacked by doppelgänger Chad Smith of Red Hot Chili Peppers

  • Television
    What To Watch On TV And Streaming Monday, May 18, 2026

    What To Watch On TV And Streaming Monday, May 18, 2026

    Tracker Season 3 Episode 21 Finally Explores the Shaw Family Secrets

    Tracker Season 3 Episode 21 Finally Explores the Shaw Family Secrets

    How Kim Wolfe’s Husband and Kids Supported Her Return to HGTV for ‘Rock the Block’ (Exclusive)

    How Kim Wolfe’s Husband and Kids Supported Her Return to HGTV for ‘Rock the Block’ (Exclusive)

    Joey King Had A Small But Memorable Role On New Girl

    Joey King Had A Small But Memorable Role On New Girl

  • Film
    Clarissa – first-look review | Little White Lies

    Clarissa – first-look review | Little White Lies

    ‘Orange-Flavoured Wedding’ by Christophe Honoré

    ‘Orange-Flavoured Wedding’ by Christophe Honoré

    IMDb Is Wrong About The Office’s Best Episode, Here’s What Should Really Be Number 1

    IMDb Is Wrong About The Office’s Best Episode, Here’s What Should Really Be Number 1

    Gentle Monster – first-look review

    Gentle Monster – first-look review

  • Literature
    You Should Know I Found a Dead Body

    You Should Know I Found a Dead Body

    Book Riot’s Deals of the Day for May 16, 2026

    Book Riot’s Deals of the Day for May 16, 2026

    Literary Hub » Lucy Ives Offers a Few Creative Prompts to Knock You Off Kilter

    Literary Hub » Lucy Ives Offers a Few Creative Prompts to Knock You Off Kilter

    A Deaf Manifesto on Motherhood

    A Deaf Manifesto on Motherhood

    Book Riot’s Deals of the Day for May 17, 2026

    Book Riot’s Deals of the Day for May 17, 2026

    Literary Hub » Lit Hub Daily: May 15, 2026

    Literary Hub » Lit Hub Daily: May 15, 2026

    Exclusive Cover Reveal of “Distortion” by Kathryn Bromwich

    Exclusive Cover Reveal of “Distortion” by Kathryn Bromwich

    Goodreads Has Summer Reading Lists Galore

    Goodreads Has Summer Reading Lists Galore

    May 11 – 15, 2026

    May 11 – 15, 2026

  • Contact
    • About
  • Home
  • US News
    The little-known Medicare surtax may hammer millions in Obamacare tax battle

    The little-known Medicare surtax may hammer millions in Obamacare tax battle

    Arkansas man arrested for allegedly threatening Walmart mass shooting

    Arkansas man arrested for allegedly threatening Walmart mass shooting

    Lindsey Graham warns Republicans who ‘try to destroy’ Trump will lose

    Lindsey Graham warns Republicans who ‘try to destroy’ Trump will lose

    Selfie video captures scary moment baseball fan at Mariners game gets hit in the skull by foul ball

    Selfie video captures scary moment baseball fan at Mariners game gets hit in the skull by foul ball

    401(k) account takeover fraud drained 1,430 in a single phone call

    401(k) account takeover fraud drained $751,430 in a single phone call

  • Politics
    A Planned Democratic Investigation Is The First Step In Trump Family Corruption Charges

    A Planned Democratic Investigation Is The First Step In Trump Family Corruption Charges

    Pete Buttigieg Totally Wrecks Trump Transportation Secretary Sean Duffy

    Pete Buttigieg Totally Wrecks Trump Transportation Secretary Sean Duffy

    The Iran War Has Broken Trump

    The Iran War Has Broken Trump

    Trump Doesn’t Have Enough Votes To Get His Ballroom Money

    Trump Doesn’t Have Enough Votes To Get His Ballroom Money

  • Business
    Anaplan CEO: AI isn’t eating software. It’s sorting it

    Anaplan CEO: AI isn’t eating software. It’s sorting it

    World Economic Forum: women’s health gets only 20% of R&D funding. We must seize this  trillion opportunity

    World Economic Forum: women’s health gets only 20% of R&D funding. We must seize this $1 trillion opportunity

    CDC to escalate Ebola response after WHO declares emergency

    CDC to escalate Ebola response after WHO declares emergency

    The top foreign holders of US debt may soon dump Treasury bonds and bring their money back home

    The top foreign holders of US debt may soon dump Treasury bonds and bring their money back home

  • Science
    Finnish Researchers Print Bone-Like Scaffolds That Let the Body Do the Rest

    Finnish Researchers Print Bone-Like Scaffolds That Let the Body Do the Rest

    Did Homo erectus and Denisovans mate? Tooth proteins hint at ancient trysts

    Did Homo erectus and Denisovans mate? Tooth proteins hint at ancient trysts

    SpaceX is about to launch tallest and most powerful rocket in history

    SpaceX is about to launch tallest and most powerful rocket in history

    The First Atomic Bomb Test in 1945 Created an Entirely New Material

    The First Atomic Bomb Test in 1945 Created an Entirely New Material

  • Technology
    South Korea’s LetinAR is building optics behind AI glasses

    South Korea’s LetinAR is building optics behind AI glasses

    The 6 Best Grills and Smokers of 2026: Smart, Portable, Pellet

    The 6 Best Grills and Smokers of 2026: Smart, Portable, Pellet

    Apple’s Siri revamp could include auto-deleting chats

    Apple’s Siri revamp could include auto-deleting chats

    Oto Smart Sprinkler Review (2026): Solar-Powered and Simple to Use

    Oto Smart Sprinkler Review (2026): Solar-Powered and Simple to Use

  • Lifestyle
    Spring Nourishment Rituals That Will Change the Way You Eat

    Spring Nourishment Rituals That Will Change the Way You Eat

    27 Easy Dishes for Your BBQ

    27 Easy Dishes for Your BBQ

    5 Summer Hosting Outfit Formulas That Make Getting Dressed Easy

    5 Summer Hosting Outfit Formulas That Make Getting Dressed Easy

    13 Healthy Summer Cookbooks for Light, Seasonal Cooking

    13 Healthy Summer Cookbooks for Light, Seasonal Cooking

  • Music
    Avohee Avoher Ignites the Night with the Electrifying “Malami”

    Avohee Avoher Ignites the Night with the Electrifying “Malami”

    The Smashing Pumpkins Announce the Rats in a Cage Tour

    The Smashing Pumpkins Announce the Rats in a Cage Tour

    Every 2026 ACMs Performance, Ranked

    Every 2026 ACMs Performance, Ranked

    Watch Will Ferrell’s ‘SNL’ monologue get hijacked by doppelgänger Chad Smith of Red Hot Chili Peppers

    Watch Will Ferrell’s ‘SNL’ monologue get hijacked by doppelgänger Chad Smith of Red Hot Chili Peppers

  • Television
    What To Watch On TV And Streaming Monday, May 18, 2026

    What To Watch On TV And Streaming Monday, May 18, 2026

    Tracker Season 3 Episode 21 Finally Explores the Shaw Family Secrets

    Tracker Season 3 Episode 21 Finally Explores the Shaw Family Secrets

    How Kim Wolfe’s Husband and Kids Supported Her Return to HGTV for ‘Rock the Block’ (Exclusive)

    How Kim Wolfe’s Husband and Kids Supported Her Return to HGTV for ‘Rock the Block’ (Exclusive)

    Joey King Had A Small But Memorable Role On New Girl

    Joey King Had A Small But Memorable Role On New Girl

  • Film
    Clarissa – first-look review | Little White Lies

    Clarissa – first-look review | Little White Lies

    ‘Orange-Flavoured Wedding’ by Christophe Honoré

    ‘Orange-Flavoured Wedding’ by Christophe Honoré

    IMDb Is Wrong About The Office’s Best Episode, Here’s What Should Really Be Number 1

    IMDb Is Wrong About The Office’s Best Episode, Here’s What Should Really Be Number 1

    Gentle Monster – first-look review

    Gentle Monster – first-look review

  • Literature
    You Should Know I Found a Dead Body

    You Should Know I Found a Dead Body

    Book Riot’s Deals of the Day for May 16, 2026

    Book Riot’s Deals of the Day for May 16, 2026

    Literary Hub » Lucy Ives Offers a Few Creative Prompts to Knock You Off Kilter

    Literary Hub » Lucy Ives Offers a Few Creative Prompts to Knock You Off Kilter

    A Deaf Manifesto on Motherhood

    A Deaf Manifesto on Motherhood

    Book Riot’s Deals of the Day for May 17, 2026

    Book Riot’s Deals of the Day for May 17, 2026

    Literary Hub » Lit Hub Daily: May 15, 2026

    Literary Hub » Lit Hub Daily: May 15, 2026

    Exclusive Cover Reveal of “Distortion” by Kathryn Bromwich

    Exclusive Cover Reveal of “Distortion” by Kathryn Bromwich

    Goodreads Has Summer Reading Lists Galore

    Goodreads Has Summer Reading Lists Galore

    May 11 – 15, 2026

    May 11 – 15, 2026

  • Contact
    • About
No Result
View All Result
WashingtonWeeklyTimes.com
No Result
View All Result
Home Technology

Slack and Teams’ Lax App Security Raises Alarms

by Admin
September 23, 2022
in Technology
Slack and Teams’ Lax App Security Raises Alarms


Collaboration apps like Slack and Microsoft Teams have become the connective tissue of the modern workplace, tying together users with everything from messaging to scheduling to video conference tools. But as Slack and Teams become full-blown, app-enabled operating systems of corporate productivity, one group of researchers has pointed to serious risks in what they expose to third-party programs—at the same time as they’re trusted with more organizations’ sensitive data than ever before.

A new study by researchers at the University of Wisconsin-Madison points to troubling gaps in the third-party app security model of both Slack and Teams, which range from a lack of review of the apps’ code to default settings that allow any user to install an app for an entire workspace. And while Slack and Teams apps are at least limited by the permissions they seek approval for upon installation, the study’s survey of those safeguards found that hundreds of apps’ permissions would nonetheless allow them to potentially post messages as a user, hijack the functionality of other legitimate apps, or even, in a handful of cases, access content in private channels when no such permission was granted.

“Slack and Teams are becoming clearinghouses of all of an organization’s sensitive resources,” says Earlence Fernandes, one of the researchers on the study who now works as a professor of computer science at the University of California at San Diego, and who presented the research last month at the USENIX Security conference. “And yet, the apps running on them, which provide a lot of collaboration functionality, can violate any expectation of security and privacy users would have in such a platform.”

When WIRED reached out to Slack and Microsoft about the researchers’ findings, Microsoft declined to comment until it could speak to the researchers. (The researchers say they communicated with Microsoft about their findings prior to publication.) Slack, for its part, says that a collection of approved apps that is available in its Slack App Directory does receive security reviews before inclusion and are monitored for any suspicious behavior. It “strongly recommends” that users install only these approved apps and that administrators configure their workspaces to allow users to install apps only with an administrator’s permission. “We take privacy and security very seriously,” the company says in a statement, “and we work to ensure that the Slack platform is a trusted environment to build and distribute apps, and that those apps are enterprise-grade from day one.”

But both Slack and Teams nonetheless have fundamental issues in their vetting of third-party apps, the researchers argue. They both allow integration of apps hosted on the app developer’s own servers with no review of the apps’ actual code by Slack or Microsoft engineers. Even the apps reviewed for inclusion in Slack’s App Directory undergo only a more superficial check of the apps’ functionality to see whether they work as described, check elements of their security configuration such as their use of encryption, and run automated app scans that check their interfaces for vulnerabilities.

Despite Slack’s own recommendations, both collaboration platforms by default allow any user to add these independently hosted apps to a workspace. An organization’s administrators can switch on stricter security settings that require the administrators to approve apps before they’re installed. But even then, those administrators must approve or deny apps without themselves having any ability to vet their code, either—and crucially, the apps’ code can change at any time, allowing a seemingly legitimate app to become a malicious one. That means attacks could take the form of malicious apps disguised as innocent ones, or truly legitimate apps could be compromised by hackers in a supply chain attack, in which hackers sabotage an application at its source in an effort to target the networks of its users. And with no access to apps’ underlying code, those changes could be undetectable to both administrators and any monitoring system used by Slack or Microsoft.



Original Source Link

Previous Post

Robot navigates indoors by tracking anomalies in magnetic fields

Next Post

Orioles hired investment bank to assess potential sale of team: report

Admin

Admin

Next Post
Orioles hired investment bank to assess potential sale of team: report

Orioles hired investment bank to assess potential sale of team: report

Trump Appointed Judge Slams The Door On Mike Lindell’s Motion Demanding Return Of Phone

Trump Appointed Judge Slams The Door On Mike Lindell's Motion Demanding Return Of Phone

Ford’s Latest Supply-Chain Problem: a Shortage of Blue Oval Badges

Ford’s Latest Supply-Chain Problem: a Shortage of Blue Oval Badges

PopularPosts

[VIDEO} ‘A League of Their Own’ on Amazon: Release Date, Trailer

[VIDEO} ‘A League of Their Own’ on Amazon: Release Date, Trailer

June 7, 2022
Human waste could help tackle a global shortage of fertiliser

Human waste could help tackle a global shortage of fertiliser

January 19, 2023
7 Things You May Not Know About ‘The Lone Ranger’

7 Things You May Not Know About ‘The Lone Ranger’

August 1, 2025
Ultimate Guide to Unforgettable Holiday Cruises: Your Perfect Getaway

Ultimate Guide to Unforgettable Holiday Cruises: Your Perfect Getaway

October 26, 2023
Every Dual-Type Pokémon With Only One Weakness

Every Dual-Type Pokémon With Only One Weakness

May 12, 2022
Kneecap’s Mo Chara Beats Terrorism Charge in England

Kneecap’s Mo Chara Beats Terrorism Charge in England

September 26, 2025

Categories

  • Business (7,411)
  • Events (9)
  • Film (7,343)
  • Lifestyle (5,267)
  • Literature (5,457)
  • Music (7,391)
  • Politics (7,246)
  • Science (6,783)
  • Technology (7,337)
  • Television (7,404)
  • Uncategorized (6)
  • US News (7,442)

RecentPosts

Avohee Avoher Ignites the Night with the Electrifying “Malami”

Avohee Avoher Ignites the Night with the Electrifying “Malami”

by Rhonda Kilpatrick
May 18, 2026

Avohee Avoher’s “Malami” pulses with dangerous energy and hypnotic seduction,...

Clarissa – first-look review | Little White Lies

Clarissa – first-look review | Little White Lies

by
May 18, 2026

Clarissa (Sophie Okonedo) seems on edge the morning of her...

What To Watch On TV And Streaming Monday, May 18, 2026

What To Watch On TV And Streaming Monday, May 18, 2026

by
May 18, 2026

CBS Every day, TVLine's What to Watch column spotlights new...

Spring Nourishment Rituals That Will Change the Way You Eat

Spring Nourishment Rituals That Will Change the Way You Eat

by
May 18, 2026

We may receive a portion of sales if you purchase...

You Should Know I Found a Dead Body

You Should Know I Found a Dead Body

by
May 18, 2026

You Should Know I Found a Dead Body Aea Varfis-van...

The Smashing Pumpkins Announce the Rats in a Cage Tour

The Smashing Pumpkins Announce the Rats in a Cage Tour

by
May 18, 2026

The Smashing Pumpkins have detailed an extensive run of concerts...

Archives

Editor's Picks

1 Book Stephen King Almost Didn’t Write Should Be Mike Flanagan’s Next Adaptation

1 Book Stephen King Almost Didn’t Write Should Be Mike Flanagan’s Next Adaptation

May 15, 2026
South Korea’s LetinAR is building optics behind AI glasses

South Korea’s LetinAR is building optics behind AI glasses

May 18, 2026
Joanna Gaines Shares Progress on Her Farmhouse Kitchen Renovation

Joanna Gaines Shares Progress on Her Farmhouse Kitchen Renovation

May 15, 2026

Browse By Category

  • Business (7,411)
  • Events (9)
  • Film (7,343)
  • Lifestyle (5,267)
  • Literature (5,457)
  • Music (7,391)
  • Politics (7,246)
  • Science (6,783)
  • Technology (7,337)
  • Television (7,404)
  • Uncategorized (6)
  • US News (7,442)

Useful Links

  • Anti-Spam Policy
  • Copyright Notice
  • DMCA Compliance
  • Earnings Disclaimer
  • Fair Use Disclaimer
  • FTC Compliance
  • Medical Disclaimer
  • Privacy Policy
  • Social Media Disclaimer
  • Terms and Conditions

Copyright © 2022 by Washington Weekly Times. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms of Use and Privacy Policy.

No Result
View All Result
  • Home
  • US News
  • Politics
  • Business
  • Science
  • Technology
  • Lifestyle
  • Music
  • Television
  • Film
  • Literature
  • Contact
    • About

Copyright © 2022 by Washington Weekly Times. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms of Use and Privacy Policy.

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT