Microsoft Warns Misconfigured Email Routing Can Enable Internal Domain Phishing
Phishing attacks are carried out by threat actors who use routing circumstances and improperly configured spoof safeguards to mimic the domains of businesses and send emails that look like they were sent internally.
According to a research released on Tuesday by the Microsoft Threat Intelligence team, threat actors have used this vector to spread a wide range of phishing messages pertaining to several phishing-as-a-service (PhaaS) platforms, including Tycoon 2FA.
Credential phishing can result from messages with lures centered around voicemails, shared documents, communications from human resources (HR) departments, password resets or expirations, and other topics.
The IT giant claimed to have seen an increase in the usage of the attack vector since May 2025 as part of opportuni...

