URL has been copied successfully!
Microsoft 365 Direct Send Bypass Lets Attackers Spoof Internal Users Without Credentials
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Microsoft 365 Direct Send Bypass Lets Attackers Spoof Internal Users Without Credentials

A Microsoft 365 email security-control bypass that lets attackers submit unauthenticated messages posing as internal users by leaving one SMTP field blank. The technique targets Exchange Online’s RejectDirectSend setting and does not represent a vulnerability in Microsoft software or in ReliaQuest systems; instead, it exposes a limitation in how the control evaluates Direct Send traffic. […] The post Microsoft 365 Direct Send Bypass Lets Attackers Spoof Internal Users Without Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

First seen on gbhackers.com

Jump to article: gbhackers.com/microsoft-365-security-bypass/

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link