Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Phishing in Microsoft 365 Exploits Empty Envelope Sender

Phishing in Microsoft 365 Exploits Empty Envelope Sender

Posted on September 4, 2026 By CWS

Microsoft 365 users are encountering a novel phishing method that exploits a specific loophole: attackers are crafting emails with an empty SMTP envelope sender. This tactic can enable unauthenticated messages to slip past Direct Send protections, while presenting email addresses that appear legitimate to employees.

Understanding the Technique

This method does not stem from a flaw in Microsoft software nor does it require compromised accounts. The technique takes advantage of how Exchange Online’s RejectDirectSend feature examines the domain in the SMTP envelope sender, rather than the visible From field address. This discrepancy allows cybercriminals to easily impersonate internal communications, bypassing a safeguard meant to block dangerous email spoofing.

Researchers at ReliaQuest uncovered this pattern in active phishing incidents and successfully replicated it within a controlled Microsoft 365 environment. According to their report, this strategy has been used across various organizations over the past year, often masquerading as internal messages such as document notices, payment requests, or voicemail alerts.

Implications for Security

While some phishing attempts might be caught by mail filters, any message that reaches its target can facilitate credential theft, malware dissemination, unauthorized financial transactions, and broader account breaches. The Direct Send feature permits devices and applications to send emails within the same Microsoft 365 tenant without needing authentication, which attackers have exploited to mimic internal users without account compromise.

In testing, ReliaQuest observed that messages with the tenant’s domain in the envelope sender were rejected, yet those using an empty sender field were accepted and processed. Although flagged as spam with a high Spam Confidence Level, such messages can occasionally land in inboxes under certain configurations.

Defensive Measures

ReliaQuest’s analysis of phishing targets from late 2025 to mid-2026 revealed a focus on executives, managers, financial personnel, and customer service roles, often engaging in tasks like handling invoices and payment instructions. Common phishing lures included file-sharing alerts, payment requests, procurement invitations, and meeting notices, sometimes utilizing SVG attachments to mimic voicemail.

To bolster defenses, organizations should maintain the RejectDirectSend feature while implementing an IP-restricted inbound connector to only allow unauthenticated Direct Send from verified devices and applications. It is also crucial to eliminate unnecessary filtering exceptions and scrutinize trusted routes and permissive rules.

Furthermore, administrators should monitor for emails with empty envelope senders paired with visible From addresses mimicking internal domains, especially when standard email authentication checks fail but delivery occurs through exceptions. Employees must verify unexpected requests for payments or documents through known communication channels before proceeding.

Staying informed about emerging malware and phishing tactics is vital. Security teams should ensure they are updated on threats within 24 hours of their emergence.

Cyber Security News Tags:cyber attacks, Cybersecurity, Direct Send, email security, email spoofing, Exchange Online, Microsoft 365, Phishing, ReliaQuest, security measures

Post navigation

Previous Post: OpenAI Agents Exploit German Wiki to Share Bypass Tactics

Related Posts

New Python RAT Mimic as Legitimate Minecraft App Steals Sensitive Data from Users Computer New Python RAT Mimic as Legitimate Minecraft App Steals Sensitive Data from Users Computer Cyber Security News
MediaTek Vulnerabilities Let Attackers Escalate Privileges Without User Interaction MediaTek Vulnerabilities Let Attackers Escalate Privileges Without User Interaction Cyber Security News
Fortinet FortiSIEM Command Injection Vulnerability (CVE-2025-25256) Fortinet FortiSIEM Command Injection Vulnerability (CVE-2025-25256) Cyber Security News
BlackSuit Ransomware Servers Attacking U.S. Critical Infrastructure Seized by Law Enforcement Seizes BlackSuit Ransomware Servers Attacking U.S. Critical Infrastructure Seized by Law Enforcement Seizes Cyber Security News
NETREAPER Offensive Security Toolkit That Wraps 70+ Penetration Testing Tools NETREAPER Offensive Security Toolkit That Wraps 70+ Penetration Testing Tools Cyber Security News
1-Click Oracle Cloud Code Editor RCE Vulnerability Lets Attackers Upload Malicious Files 1-Click Oracle Cloud Code Editor RCE Vulnerability Lets Attackers Upload Malicious Files Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark