Direct Send: How Attackers Weaponize Your Infrastructure Against You
ID: 3b791710-8f17-51dd-9912-dbb898cff309
STIX ID: report--3b791710-8f17-51dd-9912-dbb898cff309
Feed Name: KnowBe4 Blog
**Executive summary:** KnowBe4 Threat Labs observed a large Direct Send abuse campaign (≈29,785 confirmed spoofs in Jul–Aug 2026) that leverages Exchange Online's open MX endpoint to send unauthenticated emails appearing from internal addresses. Attackers used social-engineering lures (fake docs, voicemail alerts, invoices, OneDrive links) timed to business hours, rotated cloud providers, and employed reply-to mismatches and redirecting .url files to harvest credentials and enable BEC; the report includes IOCs, header indicators (X-MS-Exchange-Organization-AuthAs:Anonymous), and actionable Microsoft 365 configuration fixes such as enforcing DMARC, locking inbound connectors, and DKIM.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
