Praetorian reported an attack chain in which adversaries combine two seemingly lower-severity weaknesses—abusable public-facing email/newsletter API endpoints and verbose error handling that leaks OAuth 2.0 bearer tokens—to achieve high-impact compromise. In the first step, attackers manipulate unauthenticated JSON parameters (e.g., recipient, subject, body) in business-logic-driven endpoints (such as newsletter signups/contact forms/password resets) to force an organization’s own infrastructure to send attacker-crafted emails. Because the messages are sent by authorized systems, they pass SPF/DKIM/DMARC checks and are more likely to land in users’ primary inboxes, effectively turning trusted infrastructure into a phishing delivery mechanism.
The second step escalates impact when malformed requests (including incomplete or invalid JSON) trigger debugging responses that return stack traces and inadvertently expose OAuth access tokens used by internal services. With stolen tokens—often usable against Microsoft Graph depending on configured scopes—attackers can access Microsoft 365 resources without needing user credentials, potentially enabling broad tenant compromise. The reporting emphasizes that the protocols (SPF/DMARC) are not “broken”; rather, attackers are exploiting legitimate sending paths and poor error hygiene, illustrating how vulnerability chaining can turn medium/low issues into a critical compromise path.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
A follow-up report highlighted that combining phishing delivery weaknesses with OAuth token flaws can lead to full Microsoft 365 compromise. The coverage reinforced the impact of the attack path involving trusted email delivery and abuse of valid Microsoft Graph access tokens.
Praetorian published research describing how attackers can chain unauthenticated email-sending flaws with OAuth token exposure to compromise Microsoft 365 accounts. The write-up explained that phishing emails sent through a victim organization's own mail infrastructure can pass SPF, DKIM, and DMARC, then be combined with leaked or intercepted access tokens for broader access.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.