
← ShadowTalk: Powered by ReliaQuesthace 6 días · 30 min
One Empty Field: The Email Security Bypass Letting Attackers Impersonate Your Executives
One Empty Field: The Email Security Bypass Letting Attackers Impersonate Your Executives
Organizations rely on Microsoft 365's RejectDirectSend control to block internal email spoofing—but a structural gap lets attackers walk right past it. With nothing more than a basic Python script and an empty envelope sender, threat actors are impersonating executives, IT support, and finance teams to launch Business Email Compromise, payment fraud, and follow-on account takeover. Join hosts Alexandra Moore and John Dilgen as they discuss: How an empty email header field bypasses RejectDirec...