Microsoft detailed how Direct Send differs from sending mail directly to an Exchange Online tenant, highlighting that Direct Send is intended for internal-only delivery and relies on a tenant's accepted domains and mail flow configuration. The guidance drew attention to how Exchange Online handles messages addressed to tenant mailboxes and the trust assumptions involved when organizations route mail from on-premises systems or devices into Microsoft 365.
CERT Bulgaria later warned of the "Ghost-Sender" vulnerability affecting hybrid Exchange on-premises and Exchange Online environments, where those trust relationships can be abused to spoof email in affected configurations. The issue impacts organizations using hybrid mail setups that bridge local Exchange infrastructure with Exchange Online, raising the risk of phishing, impersonation, and fraudulent internal-looking messages unless administrators review Direct Send usage, connector settings, and hybrid mail routing controls.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
CERT Bulgaria published a warning about the Ghost-Sender vulnerability affecting hybrid Exchange On-Premises and Exchange Online configurations. The notice identifies the issue as impacting organizations using this hybrid mail setup.
Microsoft published guidance explaining the difference between Direct Send and sending directly to an Exchange Online tenant, including how mail routing works in these configurations. This documentation is relevant to hybrid Exchange deployments affected by later Ghost-Sender reporting.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
govcert.bg
Open sourcetechcommunity.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.