Security bug allows anyone to spoof Microsoft employee emails
ID: af8e4cd2-32d1-524e-bffa-c9a826085b38
STIX ID: report--af8e4cd2-32d1-524e-bffa-c9a826085b38
Feed Name: TechCrunch Security News
A researcher reported an unpatched email‑spoofing bug that can impersonate Microsoft corporate email accounts for messages sent to Outlook users; the researcher said Microsoft initially could not reproduce the issue, so he publicized the finding on X while TechCrunch withheld technical details to avoid enabling abuse. The flaw potentially affects Outlook’s large user base (Microsoft cites ~400 million users), but there is no public evidence yet of widespread malicious exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
