logo

Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address

ID: e1a67cbe-15f0-5c7b-8284-9214b7ca3243

STIX ID: report--e1a67cbe-15f0-5c7b-8284-9214b7ca3243

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-06-09

Date Updated: 2026-06-15

Author: Alexander Culafi

...
...

InfoGuard reported a widespread Exchange Online/hybrid misconfiguration called "Ghost-Sender" that lets attackers send emails appearing to come from any internal or external address (including CEO or noreply accounts) by leveraging external MX records; SPF/DKIM/DMARC are ineffective in this scenario. The issue is trivial to exploit (a one-line PowerShell) and researchers say Microsoft acknowledged related active abuse; mitigations (partner connector, mail flow rules, disabling Direct Send) exist but are underapplied across organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.