Bottom line: Security leaders should prioritize alerting employees about M365 phishing campaigns, especially those targeting US businesses, to minimize potential losses.
What's happening: KnowBe4 researchers discovered a phishing campaign that leverages Microsoft 365's Direct Send feature to send malicious emails, primarily targeting US businesses, including Fortune 500 companies, during Eastern Business Hours.
What to do: Security leaders should review and update their M365 Direct Send policies to restrict access to employees, and consider implementing employee education programs to raise awareness about phishing attacks, especially those targeting US businesses. -------------------------------------------------------------------- Please do the rewrite. I'll provide the next article.