Slack users targeted for phishing attacks – here’s how to stay protected


Slack users have been warned to take extra care when using the online collaboration service after researchers uncovered worrying security risks.
According to an AT&T AlienLabs report, incoming ‘webhooks’, which are used to connect from third-party apps to post messages on Slack, can be hijacked to carry out phishing attacks.
A compromised webhook not only allows unauthorized users to send messages to all the Slack channels, but it can also alter channel posting permissions.
Since webhooks cannot carry data themselves, hackers could easily exploit these vulnerabilities to con Slack users into installing malicious apps, allowing a potential entry route to steal data from their workspace.
Webhooks vulnerability
The researchers showed how a simple application created with the aim to phish data can be shared via spam messages to multiple Slack channels. Once a user installs the malicious application, it can then easily exfiltrate data and send it back to the hackers.
Also, once a malicious app is installed on a system, it can be used to send messages on behalf of the user, making other contacts believe the app to be trustworthy.
Since Slack allows users to install third-party apps to use in conjunction with the platform by default, the researchers recommend that workspace owners should restrict users from installing third-party apps using Slack’s inbuilt whitelisting options in order to mitigate the threat.
Mandatory approval by Admins before downloading and installing applications that have not gone through Slack’s security review process is also recommended to limit any potential threats.
Monitoring data with the help of security analytics platforms can also raise an alarm if:
- Multiple users install the same app in a short period of time
- Installation of applications using high-risk scopes
- Detection of app_scopes_expanded when a previously installed app requires new scopes
- Detection of uncommon calls that could be used for data exfiltration such as manual_export_started, an action that exports workspace data
Experts also suggest that Slack should by default limit the functionalities of applications that are not reviewed, and that incoming webhooks should be allowed to work in the defined channel.
In response to the findings Slack has said that, “We proactively scrape GitHub for publicly exposed webhooks and invalidate them. Webhooks are safe as long as they remain secret since the webhook URL itself is unguessable. We allow teams to require admin approvals on all apps, and recommend they establish and follow basic security diligence procedures before permitting apps to be added into a workspace.”
It advised users to “establish and follow basic security diligence procedures before permitting apps to be added into a workspace.”
Via: AT&T AlienLabs
Slack users have been warned to take extra care when using the online collaboration service after researchers uncovered worrying security risks. According to an AT&T AlienLabs report, incoming ‘webhooks’, which are used to connect from third-party apps to post messages on Slack, can be hijacked to carry out phishing attacks.…
Recent Posts
- HubSpot and Canva team up to level the creative playing field
- EV truck maker Nikola goes bust
- Apple TV+ releases a gritty new crime drama trailer for Dope Thief that looks like a stylish version of The Wire
- NVIDIA GeForce 5070 Ti review: A ‘sensible’ 4K powerhouse for $749
- The women who made America’s microchips and the children who paid for it
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010