Microsoft 365 ‘Direct Send’ abused to send phishing as internal users

An ongoing phishing campaign abuses a little‑known feature in Microsoft 365 called “Direct Send” to evade detection by email security and steal credentials. […]

Source:: BleepingComputer