logo

Hackers Abuse Microsoft 365’s Direct Send Feature to Deliver Internal Phishing Attacks

ID: a3d256db-0a4d-53d3-9a54-e68efd5b4c70

STIX ID: report--a3d256db-0a4d-53d3-9a54-e68efd5b4c70

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2025-08-02

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

### Executive summary Threat actors are abusing Microsoft 365 Direct Send to send internally spoofed phishing emails by relaying messages through compromised Windows Server hosts and unsecured third-party email security appliances, enabling delivery without valid tenant credentials and bypassing standard email protections; the report includes technical detail on the attack flow, IOCs (exposed ports, compauth=fail detection), and recommended mitigations such as disabling Direct Send.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.