Best of the Worst: Five Attacks That Cleared Authentication and Landed Anyway

Best of the Worst: Five Attacks That Cleared Authentication and Landed Anyway

TL;DR This week's pattern is authentication-passing phishing. The five attacks below cleared SPF, DKIM, DMARC, or some combination of them, and landed in inboxes anyway. One came from a purpose-built Microsoft 365 ...
Best of the Worst: The Week Your Security Tools Became the Disguise

Best of the Worst: The Week Your Security Tools Became the Disguise

TL;DR This week's Attack of the Day posts revealed a clear pattern: attackers are deliberately routing attacks through legitimate security and platform infrastructure so the tools themselves become trust signals. TitanHQ and ...
The DocuSign Email That Wasn't - A Three-Redirect Credential Harvest

The DocuSign Email That Wasn’t – A Three-Redirect Credential Harvest

TL;DR Attackers sent a convincing DocuSign notification with a "Review & Sign" button that chained through Google Maps redirects to an Amazon S3-hosted credential harvesting page. The redirect chain defeated URL scanners, ...
Microsoft and IRONSCALES Crack Down on the Direct Send Exploit

Microsoft and IRONSCALES Crack Down on the Direct Send Exploit

Back in Part 1, we walked through how attackers are using Microsoft 365’s Direct Send feature to spoof internal emails, making those messages look like they’re coming from a trusted domain ...
Inside Job: Attackers Are Spoofing Emails with M365’s Direct Send

Inside Job: Attackers Are Spoofing Emails with M365’s Direct Send

Over the past three months, our threat analysts have noticed a significant spike in attackers abusing Microsoft 365’s Direct Send feature—a tool intended for devices like printers or scanners to send internal ...