// Microsoft 365MEDIUM
ReliaQuest disclosed a Microsoft 365 email security control bypass affecting the RejectDirectSend setting in Exchange Online. Attackers can bypass authentication requirements and spoof internal users by submitting messages with a null SMTP envelope sender (MAIL FROM:<>), enabling convincing spearphishing attacks that appear to originate from internal addresses. The bypass has been observed in active campaigns since September 2025, targeting executives, managers, finance teams, and procurement personnel with lures including payment requests and file-sharing notices.
// Get alerts for Microsoft 365