FCM Message Notifications

%3CLINGO-SUB%20id%3D%22lingo-sub-1615501%22%20slang%3D%22en-US%22%3EFCM%20Message%20Notifications%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1615501%22%20slang%3D%22en-US%22%3E%3CP%3EA%20couple%20of%20our%20users%20received%20random%20notifications%20on%20the%20Teams%20mobile%20app%20this%20morning.%20The%20notification%20states%20%22FCM%20Message%22.%20Anyone%20have%20an%20idea%20what's%20going%20on%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1615501%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EMicrosoft%20Teams%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1615508%22%20slang%3D%22en-US%22%3ERe%3A%20FCM%20Message%20Notifications%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1615508%22%20slang%3D%22en-US%22%3EJust%20found%20this%20thread%20on%20Reddit%20--%26gt%3B%20%3CA%20href%3D%22https%3A%2F%2Fwww.reddit.com%2Fr%2FMicrosoftTeams%2Fcomments%2Fihghrq%2Ftest_notification_fcm%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.reddit.com%2Fr%2FMicrosoftTeams%2Fcomments%2Fihghrq%2Ftest_notification_fcm%2F%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1615546%22%20slang%3D%22en-US%22%3ERe%3A%20FCM%20Message%20Notifications%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1615546%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F657584%22%20target%3D%22_blank%22%3E%40SuleimanDC%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20received%205%20notifications%20this%20morning%20%22FCM%20Messages%20Test%20Notifications!!!!%22%3C%2FP%3E%3CP%3Eseems%20it%20is%20related%20to%20an%20exploit%20lets%20hope%20that%20Microsoft%20or%20Google%20plug%20it%20soon%2C%20otherwise%20I'll%20be%20uninstalling%20the%20Teams%20app%20on%20my%20phone.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1615577%22%20slang%3D%22en-US%22%3ERe%3A%20FCM%20Message%20Notifications%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1615577%22%20slang%3D%22en-US%22%3E%3CP%3EHave%20had%207%20in%20UK%20over%20about%2015%20minutes%20from%2008%3A00%20approx%20today%20(27.8.2020).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EClearly%20widespread%20and%20seems%20to%20be%20a%20Google%20Firebase%20vulnerability%20according%20to%20posts%20on%20Reddit%2C%20etc.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EConcerned%20this%20may%20lead%20to%20attempts%20at%20phishing.%26nbsp%3B%20Please%20fix%20ASAP!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1615584%22%20slang%3D%22en-US%22%3ERe%3A%20FCM%20Message%20Notifications%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1615584%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F657584%22%20target%3D%22_blank%22%3E%40SuleimanDC%3C%2FA%3E%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3EMicrosoft%20just%20sent%20this%20out%20so%20they%20are%20investigating.%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22ashleyw1490_0-1598516569643.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F214942iDB7CA79BCD46E839%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22ashleyw1490_0-1598516569643.png%22%20alt%3D%22ashleyw1490_0-1598516569643.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1615586%22%20slang%3D%22en-US%22%3ERe%3A%20FCM%20Message%20Notifications%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1615586%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F657584%22%20target%3D%22_blank%22%3E%40SuleimanDC%3C%2FA%3E%26nbsp%3B-%20It%20looks%20like%20this%20is%20related%20to%20%3CA%20href%3D%22https%3A%2F%2Fwww.androidpolice.com%2F2020%2F08%2F25%2Fhangouts-users-shouldnt-panic-about-mysterious-fcm-notifications%2F%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ea%20known%20Firebase%20bug%3C%2FA%3E.%26nbsp%3B%20There%20are%20a%20number%20of%20people%20%3CA%20href%3D%22https%3A%2F%2Fwww.reddit.com%2Fr%2FMicrosoftTeams%2Fcomments%2Fihghrq%2Ftest_notification_fcm%2F%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ereporting%20Teams%20alerts%20on%20Android%20devices%3C%2FA%3E.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1615588%22%20slang%3D%22en-US%22%3ERe%3A%20FCM%20Message%20Notifications%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1615588%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F385593%22%20target%3D%22_blank%22%3E%40MSNEC%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20also%20received%20these%20messages%20a%20little%20under%20an%20hour%20ago%20and%20this%20problem%20seems%20be%20on%20a%20global%20level.%3C%2FP%3E%3CP%3ESeems%20to%20me%20like%20they%20should%20change%20their%20token%20(API%20key)%20so%20that%20it%20isn't%20as%20easily%20exploited.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20article%20was%20published%2017th%20August%202020%20and%20as%20far%20as%20I%20can%20tell%20is%20the%20base%20idea%20for%20these%20exploits%3A%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fabss.me%2Fposts%2Ffcm-takeover%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fabss.me%2Fposts%2Ffcm-takeover%2F%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELet%20us%20hope%20that%20this%20will%20be%20fixed%20with%20an%20update%20to%20the%20apps.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1615770%22%20slang%3D%22en-US%22%3ERe%3A%20FCM%20Message%20Notifications%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1615770%22%20slang%3D%22en-US%22%3EI%20am%20one%20of%20the%20person's%20received%20the%20messages%20around%2010%20notifications%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1615788%22%20slang%3D%22en-US%22%3ERe%3A%20FCM%20Message%20Notifications%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1615788%22%20slang%3D%22en-US%22%3EJust%20to%20inform%20that%20I%20received%207%20messages%20in%20Brazil%20this%20morning%20(Aug%2027%2C%202020).%3CBR%20%2F%3E%22FCM%20Messages%20Test%20Notificationsss%22%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1615803%22%20slang%3D%22en-US%22%3ERe%3A%20FCM%20Message%20Notifications%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1615803%22%20slang%3D%22en-US%22%3EGot%20it%20too.%20Australia%20user.%206%20messages%20at%205pm%2C%20and%20for%20a%20few%20mins%20after%2C%20at%20UTC%2B10%20time.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1615875%22%20slang%3D%22en-US%22%3ERe%3A%20FCM%20Message%20Notifications%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1615875%22%20slang%3D%22en-US%22%3EThat%20document%20has%20multiple%20spelling%20errors.%20Doesn't%20seem%20legit.%3CBR%20%2F%3E%3CBR%20%2F%3EBe%20weary.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1615878%22%20slang%3D%22en-US%22%3ERe%3A%20FCM%20Message%20Notifications%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1615878%22%20slang%3D%22en-US%22%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F772944%22%20target%3D%22_blank%22%3E%40ashleyw1490%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EThat%20document%20has%20multiple%20spelling%20and%20grammatical%20issues.%20I%20wouldn't%20trust%20it.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1615881%22%20slang%3D%22en-US%22%3ERe%3A%20FCM%20Message%20Notifications%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1615881%22%20slang%3D%22en-US%22%3EDon't%20trust%20that%20document.%20It%20us%20multiple%20spelling%20and%20grammatical%20issues.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1615910%22%20slang%3D%22en-US%22%3ERe%3A%20FCM%20Message%20Notifications%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1615910%22%20slang%3D%22en-US%22%3E%3CP%3EI%20too%20faced%20the%20same%20issue.%20Today%20in%20the%20afternoon%2C%20I%20received%20at%20least%208%20notifications-%20%22Test%20Notificationsss!!!%22%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F657584%22%20target%3D%22_blank%22%3E%40SuleimanDC%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1615908%22%20slang%3D%22en-US%22%3ERe%3A%20FCM%20Message%20Notifications%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1615908%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F772944%22%20target%3D%22_blank%22%3E%40ashleyw1490%3C%2FA%3E%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3EDo%20you%20have%20the%20link%20for%20that%20alert%3F%20I%20would%20like%20to%20see%20if%20any%20updates.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

A couple of our users received random notifications on the Teams mobile app this morning. The notification states "FCM Message". Anyone have an idea what's going on? 

 

 

25 Replies

@SuleimanDC 

 

I received 5 notifications this morning "FCM Messages Test Notifications!!!!"

seems it is related to an exploit lets hope that Microsoft or Google plug it soon, otherwise I'll be uninstalling the Teams app on my phone.

Have had 7 in UK over about 15 minutes from 08:00 approx today (27.8.2020).

 

Clearly widespread and seems to be a Google Firebase vulnerability according to posts on Reddit, etc.

 

Concerned this may lead to attempts at phishing.  Please fix ASAP!

@SuleimanDC 

Microsoft just sent this out so they are investigating. 

ashleyw1490_0-1598516569643.png

 

@SuleimanDC - It looks like this is related to a known Firebase bug.  There are a number of people reporting Teams alerts on Android devices.

@MSNEC 

I have also received these messages a little under an hour ago and this problem seems be on a global level.

Seems to me like they should change their token (API key) so that it isn't as easily exploited.

 

This article was published 17th August 2020 and as far as I can tell is the base idea for these exploits:

https://abss.me/posts/fcm-takeover/

 

Let us hope that this will be fixed with an update to the apps.

I am one of the person's received the messages around 10 notifications
Just to inform that I received 7 messages in Brazil this morning (Aug 27, 2020).
"FCM Messages Test Notificationsss"
Got it too. Australia user. 6 messages at 5pm, and for a few mins after, at UTC+10 time.
@ashleyw1490

That document has multiple spelling and grammatical issues. I wouldn't trust it.

@ashleyw1490 

Do you have the link for that alert? I would like to see if any updates.

I too faced the same issue. Today in the afternoon, I received at least 8 notifications- "Test Notificationsss!!!" @SuleimanDC 

@Bmandad4u 

If you say so.

Three news articles about this:

https://cybernews.com/security/exposed-google-keys-leaves-billions-of-users-open-to-mass-spam-and-ph...

https://portswigger.net/daily-swig/google-firebase-messaging-vulnerability-allowed-attackers-to-send...

https://code2care.org/q/fcm-messages-test-notification-microsoft-teams-google-hangouts-push-alert-fi...

The people that found the exploit:

https://twitter.com/y_sodha

https://twitter.com/absshax

 

EDIT: I'm also not too hasty to say that something written in a language that isn't the writers native tongue is untrue. Not everyone is blessed with the understanding of all languages in the world

Hi @Raffe80 

That was a screen shot from our 365 service health page, 

This is the latest:

ashleyw1490_0-1598527688491.png

 

@Raffe80 

if you have access to the  office365 admin portal it can be found on this page https://admin.microsoft.com/AdminPortal/Home#/servicehealth

 

 
Woke up to this as well

Also got seven of these, each with more s added to notifications. 

Just now got many notifications saying- "Testing notification from Microsoft to investigate the problem". Is it really Microsoft?

@SuleimanDC 

 

 

Hi There,

 

I am also getting the same alerts from today morning. I have received 14 Notification today.

Its this kind of spam/attack!!!!