Hackers Abuse Microsoft 365’s Direct Send Feature to Deliver Internal Phishing Attacks
ID: a3d256db-0a4d-53d3-9a54-e68efd5b4c70
STIX ID: report--a3d256db-0a4d-53d3-9a54-e68efd5b4c70
Feed Name: cybersecurityNews.com
### Executive summary Threat actors are abusing Microsoft 365 Direct Send to send internally spoofed phishing emails by relaying messages through compromised Windows Server hosts and unsecured third-party email security appliances, enabling delivery without valid tenant credentials and bypassing standard email protections; the report includes technical detail on the attack flow, IOCs (exposed ports, compauth=fail detection), and recommended mitigations such as disabling Direct Send.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
