The attackers exploit Microsoft 365's Direct Send feature, a legitimate tool for devices and legacy applications to send emails without a dedicated account.
The "beehive" attacks, attributed to the Russian group Laundry Bear (also known as TA488 and Void Blizzard), exploit a flaw in Zimbra webmail, allowing attackers to compromise systems simply by viewing a crafted email.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.