Cloud Email Filtering Bypass Attack Works 80% of the Time
ID: e9729c32-d253-5fc4-9208-995907991919
STIX ID: report--e9729c32-d253-5fc4-9208-995907991919
Feed Name: Dark Reading
Threat Score
Researchers presented a paper showing that common cloud-based email filtering setups are frequently misconfigured—allowing attackers to bypass filters in ~80% of examined Google- and Microsoft-hosted domains—which substantially increases phishing risk; the paper details causes (confusing/incomplete vendor documentation and permissive admin settings) and recommends mitigations (restrict mail acceptance to filter IPs, properly configure SPF/DKIM/DMARC, and use ARC).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
