What is EchoSpoofing?: Proofpoint Email Routing Exploit
ID: 5a7684aa-79f1-5c95-a02f-f1792e36addb
STIX ID: report--5a7684aa-79f1-5c95-a02f-f1792e36addb
Feed Name: Security Boulevard
Threat Score
PowerDMARC outlines a Proofpoint email routing vulnerability (named "EchoSpoofing") discovered in March 2024 where a configurable relay allowed emails from any Microsoft 365 tenant to be re-authenticated with valid DKIM signatures; attackers leveraged attacker-controlled Office 365 tenants to send spoofed phishing emails that passed SPF/DKIM/DMARC and reached recipients, affecting well-known brands and prompting Proofpoint to add controls to restrict permitted M365 tenants.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
