Hackers are exploiting users with MS Outlook: report
The Hindu
Outlook does not require email authentication such as SPF or DKIM checks, indicating it prioritises productivity over security
Malicious actors are using social engineering tactics to exploit Microsoft Outlook’s vulnerability and send emails to users, making impersonators seem credible, according to security firm Avanan.
(Sign up to our Technology newsletter, Today's Cache, for insights on emerging themes at the intersection of technology, business and policy. Click to subscribe for free.)
In one attack, a test spoof email bypassed Outlook’s security layers and even seemed like an authentic email from a legitimate user, alongside displaying the Active Directory address. This address contains photos, files shared between users, recipients’ email addresses and phone numbers.