logo

Ghost-Sender Flaw Exposes Exchange Online Users to Sender Spoofing Attacks

ID: 9d86e004-ec70-5830-9604-fc7ab5f6f3ff

STIX ID: report--9d86e004-ec70-5830-9604-fc7ab5f6f3ff

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: Divya

...
...

Ghost-Sender is a vulnerability in Exchange Online that enables large-scale email spoofing by bypassing SPF/DKIM/DMARC protections in environments using external MX records or third-party filtering. Researchers demonstrated simple SMTP/PowerShell exploitation, found significant exposure among tested tenants, and observed signs of active exploitation; recommended mitigations include strict Partner Organization connectors, transport rules, disabling Direct Send where appropriate, and validating defenses with the public testing tool.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.