Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address
ID: e1a67cbe-15f0-5c7b-8284-9214b7ca3243
STIX ID: report--e1a67cbe-15f0-5c7b-8284-9214b7ca3243
Feed Name: Dark Reading
InfoGuard reported a widespread Exchange Online/hybrid misconfiguration called "Ghost-Sender" that lets attackers send emails appearing to come from any internal or external address (including CEO or noreply accounts) by leveraging external MX records; SPF/DKIM/DMARC are ineffective in this scenario. The issue is trivial to exploit (a one-line PowerShell) and researchers say Microsoft acknowledged related active abuse; mitigations (partner connector, mail flow rules, disabling Direct Send) exist but are underapplied across organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
