No Authorization Needed For this Microsoft Feature - Threat Wire

Quick Overview

Microsoft 365's Direct Send feature has a vulnerability allowing unauthenticated external actors to send spoofed internal emails, bypassing phishing filters. Additionally, eight new printer vulnerabilities, including one unfixable by firmware updates, affect over 748 models, primarily Brother, allowing attackers to generate default administrator passwords and potentially access sensitive print data. A new set of Citrix NetScaler vulnerabilities, dubbed "CitrixBleed 2," are actively exploited in the wild to bypass MFA and hijack user sessions, despite Citrix's initial claims.

Key Points: Microsoft 365's Direct Send feature allows external actors to send spoofed internal emails without authentication, bypassing phishing filters. Varonis Threat Labs discovered this M365 phishing campaign actively exploited in the wild since May 2025. Eight new vulnerabilities affect over 748 printer models from five manufacturers, with 689 being Brother printers. One critical printer vulnerability (CVE-2024-51978) allows remote unauthenticated attackers to generate default administrator passwords from a device's serial number. This critical printer vulnerability cannot be fully remediated via firmware and requires a manufacturing process change for new models; older models have only a workaround. A new set of Citrix NetScaler vulnerabilities, including CVE-2025-5777 (dubbed "CitrixBleed 2"), allows out-of-bounds memory reads to steal tokens, bypass MFA, and hijack user sessions. ReliaQuest assesses with medium confidence that attackers are actively exploiting CitrixBleed 2 to gain initial access to targeted environments, contradicting Citrix's initial public statements.

Context: This "Threat Wire" episode, dated June 30, 2025, covers recent cybersecurity vulnerabilities impacting widely used enterprise technologies. The host discusses findings from Varonis Threat Labs regarding a Microsoft 365 email spoofing flaw and new research on printer vulnerabilities, particularly affecting Brother models. The episode also provides an update on Citrix NetScaler vulnerabilities, including a new iteration of the "CitrixBleed" exploit, highlighting discrepancies between vendor statements and active exploitation reports.

Raw markdown version of this recap