
Hackers Bypass Microsoft 365 RejectDirectSend With Empty SMTP Sender to Spoof Internal Emails
Threat actors can bypass Microsoft 365’s RejectDirectSend protection by using an empty SMTP envelope sender, allowing phishing messages to appear as if they were sent by trusted internal users, according to ReliaQuest. RejectDirectSend is an Exchange Online control designed to stop unauthenticated Direct Send emails that claim to originate from an organization’s own Microsoft 365 […]
The post Hackers Bypass Microsoft 365 RejectDirectSend With Empty SMTP Sender to Spoof Internal Emails appeared first on Cyber Security News.