• Home
  • Privacy Policy
  • Terms and Conditions
  • DMCA
  • Disclaimer
  • Contact us
Thursday, September 24, 2026
No Result
View All Result
NEWSLETTER defal
Lebanon Hub
NEWSLETTER
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up
No Result
View All Result
Lebanon Hub
No Result
View All Result

Hackers Favor US Eastern Business Hours in M365 Phishing Campaign

September 24, 2026
in Cyber Security
0
Home Cyber Security
0
VIEWS
Share on FacebookShare on Twitter


A phishing campaign abusing Microsoft 365’s Direct Send feature was observed to follow US Eastern business hours.

The campaign was uncovered by the KnowBe4 Threat Lab team, who observed 29,785 confirmed phishing emails abusing the Direct Send functionality across July and August 2026.

The researchers highlighted the “distinctly human pattern” of its delivery: attackers were observed to be particularly active from Monday to Tuesday during US Eastern business hours, with volumes peaking just before noon, dipping and then reaching their highest point at around 2pm EST.

Attackers Abuse Microsoft Direct Send Function

Direct Send is a legitimate Microsoft 365 feature designed to allow devices such as printers and scanners, as well as legacy applications, to send emails without a dedicated account.

Attackers exploited this feature to send emails that appear to originate from trusted internal addresses, such as HR, accounting or admin.

Such Direct Send attacks allow the perpetrator to spread malicious payloads without the need to compromise an employee account or obtain their credentials. It also enables them to bypass the targeted organization’s normal email security gateway by connecting directly to its Exchange Online MX endpoint.

“While authentication checks may detect that something is wrong, organizations using a domain-based message authentication, reporting and conformance (DMARC) monitoring policy can still allow the message to be delivered,” said the KnowBe4 report, published on September 10.

The KnowBe4 researchers found that approximately 35% of emails it classified as phishing emails carried attachments, “virtually all of which” classified as threats.

These included fake document requests, internal voicemail alerts, invoices and payment approvals and fake OneDrive file shares.

Additionally, 4023 of malicious emails used a reply-to address pointing to a different domain, routing employee responses directly to the attacker.

In one instance, a phishing email reached 900 recipients in a single send.

To avoid being targeted by this kind of phishing campaigns, the KnowBe4 researchers recommended that organizations look for the Exchange header “X-MS-Exchange-Organization-AuthAs: Anonymous,” a sign suggesting the email arrived through an unauthenticated delivery path.

Other measures security teams can take include enforcing a strict DMARC policy by changing it from p = none to p = reject, which blocks spoofed messages claiming to come from your domain.

Organizations should also restrict legitimate senders through Exchange Online connectors, allowing only approved IP addresses, and close the Direct Send pathway if it is not required. Enabling DomainKeys identified mail (DKIM) signing further verifies outbound emails and gives DMARC the information needed to detect and reject unauthorized messages.

Image credits: gguy / Vladimka production / Shutterstock.com



Source link

Next Post

Google Maps wants to help prevent users from running stop signs

Beirut, LB
28°
Partly Cloudy
06:2218:40 EEST
Feels like: 30°C
Wind: 11km/h SW
Humidity: 58%
Pressure: 1011.18mbar
UV index: 7
SatSunMon
30°C / 25°C
31°C / 26°C
31°C / 26°C
powered by Weather Atlas

Recent News

South Korea’s KB Securities Plans to Move Traditional Assets Onchain

September 24, 2026

Discord Ban in the Philippines Lifted Less Than 24 Hours After Taking Effect – GamingPH.com

September 24, 2026

Sandwalkers Sends Adventurers Into A World Where The Weather Wants You Dead

September 24, 2026

Star Wars Zero Company Review (PS5)

September 24, 2026

A new Monster Hunter World seamless co-op mod tackles the RPG’s most frustrating issue

September 24, 2026

September’s Collabs Corner: Naruto in Free Fire, KPop Demon Hunters in Monopoly Go, Duo goes to battle in Brawl Stars, and more

September 24, 2026

Inside Chrissy Metz’s weight-loss transformation – from childhood struggles to her GLP-1 journey

September 24, 2026

Pakistan hits Afghanistan sites after drone attacks

September 24, 2026
Lebanon Hub

Get the Latest Lebanon News and world News on LebanonHub.com. Local News, Sports, Technology, Music, Celebrity, Gaming News and Cryptocurrency Updates.

Category

  • Altcoin
  • Australia
  • Bitcoin
  • Blockchain
  • Celebrity
  • Cyber Security
  • Ethereum
  • Exchange
  • Litecoin
  • Local News
  • Mobile
  • Movies
  • Music
  • New Released
  • PC
  • PlayStation
  • Reviews
  • Sports
  • Startups
  • Technology
  • TV
  • XBOX

Recent News

South Korea’s KB Securities Plans to Move Traditional Assets Onchain

September 24, 2026

Discord Ban in the Philippines Lifted Less Than 24 Hours After Taking Effect – GamingPH.com

September 24, 2026
  • Home
  • DMCA
  • Disclaimer
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2022 - Lebanon Hub.

No Result
View All Result
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up

Copyright © 2022 - Lebanon Hub.