Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Exploit Microsoft 365 Direct Send to Evade Filters and Steal Data

Cybercriminals are increasingly exploiting a legitimate Microsoft 365 feature designed for enterprise convenience, turning Exchange Online's Direct Send into a vector for phishing and business email compromise attacks.

Cybercriminals are increasingly exploiting a legitimate Microsoft 365 feature designed for enterprise convenience, turning Exchange Online's Direct Send into a vector for phishing and business email compromise attacks.

Security researchers have observed that malicious actors leverage this pathway to bypass authentication checks and deliver messages that evade traditional security controls.

Microsoft 365 Exchange Online's Direct Send was developed to address a practical enterprise challenge. Devices and legacy applications, such as multifunction printers, scanners, and older software, need to send email within corporate networks but lack modern authentication capabilities.

Direct Send allows these devices to bypass rigorous authentication and security screening, preserving business workflows. However, this has become an exploitable vulnerability. Cisco Talos and other security vendors have reported increased malicious activity leveraging Direct Send for phishing campaigns and business email compromise attacks.

Microsoft has acknowledged these security implications and introduced a Public Preview of the RejectDirectSend control, signaling future improvements such as Direct Send-specific usage reports and a potential "default-off" posture for new tenants.

How Attackers Exploit the Trusted Pathway

Direct Send abuse involves the exploitation of a trusted communication channel. Attackers emulate legitimate device or application traffic, sending unauthenticated messages that appear to originate from internal accounts.

Research reveals that attackers frequently impersonate internal users, executives, or IT help desks. Business-themed social engineering lures, such as task approvals and payment prompts, are common.

Microsoft 365 Exchange Online's Direct Send was developed to address a practical enterprise challenge.
Aiden Sinclair · Thehackingpost

Modern attacks incorporate techniques to evade content filters, such as QR codes embedded in PDFs and obfuscated attachments, which redirect victims to credential harvesting pages.

The core vulnerability lies in Direct Send's exemption from standard email domain sender verification. Authentication mechanisms like DKIM, SPF, and DMARC typically protect email recipients, but Direct Send bypasses these checks.

Real-world examples include spoofed notifications that bypassed sender verification due to Direct Send, allowing malicious messages through.

This creates challenges for enterprises, as many organizations rely on Direct Send for legacy systems. Disabling it without proper planning may disrupt business operations.

To counter Direct Send exploitation, security experts recommend a layered defense strategy. Organizations should disable or restrict Direct Send where feasible, beginning with a thorough inventory of current dependencies.

Administrators should review internal device inventories, SPF records, and connector configurations. Microsoft has provided tools to enable the RejectDirectSend control.

Advertisement

Migration to authenticated SMTP is the most secure long-term solution. Organizations should adopt authenticated SMTP client submission on port 587 for devices capable of storing modern credentials.

For devices unable to use authenticated submission, deploy SMTP relays with tightly scoped source IP restrictions.

Strengthening authentication and alignment provides additional protection. Maintain SPF with authorized sending IPs and enforce DKIM signing. Monitor DMARC reports for unauthenticated traffic.

Enhance policy, access, and monitoring to restrict unauthorized SMTP traffic. Use Conditional Access policies to block legacy authentication paths and configure alerts for unexpected internal domain messages.

These defenses, combined with platform controls, aim to reduce attacker dwell time and improve detection-to-remediation as organizations work to secure this feature.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories