# No Authorization Needed For this Microsoft Feature - Threat Wire

Source: https://www.youtube.com/watch?v=aeLfTB5K72g
Recap page: https://rapidrecap.app/video/aeLfTB5K72g
Generated: 2025-07-17T07:33:40.345+00:00

---
## Quick Overview

Microsoft 365's Direct Send feature has a vulnerability allowing unauthenticated external actors to send spoofed internal emails, bypassing phishing filters. Additionally, eight new printer vulnerabilities, including one unfixable by firmware updates, affect over 748 models, primarily Brother, allowing attackers to generate default administrator passwords and potentially access sensitive print data. A new set of Citrix NetScaler vulnerabilities, dubbed "CitrixBleed 2," are actively exploited in the wild to bypass MFA and hijack user sessions, despite Citrix's initial claims.

**Key Points:**
- Microsoft 365's Direct Send feature allows external actors to send spoofed internal emails without authentication, bypassing phishing filters.
- Varonis Threat Labs discovered this M365 phishing campaign actively exploited in the wild since May 2025.
- Eight new vulnerabilities affect over 748 printer models from five manufacturers, with 689 being Brother printers.
- One critical printer vulnerability (CVE-2024-51978) allows remote unauthenticated attackers to generate default administrator passwords from a device's serial number.
- This critical printer vulnerability cannot be fully remediated via firmware and requires a manufacturing process change for new models; older models have only a workaround.
- A new set of Citrix NetScaler vulnerabilities, including CVE-2025-5777 (dubbed "CitrixBleed 2"), allows out-of-bounds memory reads to steal tokens, bypass MFA, and hijack user sessions.
- ReliaQuest assesses with medium confidence that attackers are actively exploiting CitrixBleed 2 to gain initial access to targeted environments, contradicting Citrix's initial public statements.

![Screenshot at 1:50: Text overlay describing the critical printer vulnerability CVE-2024-51978, which allows generating default administrator passwords from a device's serial number.](https://ss.rapidrecap.app/screens/aeLfTB5K72g/00-01-50.png)

**Context:** This "Threat Wire" episode, dated June 30, 2025, covers recent cybersecurity vulnerabilities impacting widely used enterprise technologies. The host discusses findings from Varonis Threat Labs regarding a Microsoft 365 email spoofing flaw and new research on printer vulnerabilities, particularly affecting Brother models. The episode also provides an update on Citrix NetScaler vulnerabilities, including a new iteration of the "CitrixBleed" exploit, highlighting discrepancies between vendor statements and active exploitation reports.

## Detailed Analysis

The video details three significant cybersecurity threats. First, Microsoft 365's "Direct Send" feature, intended for internal device email sending without authentication, has been exploited by attackers since May 2025. Varonis Threat Labs uncovered a phishing campaign leveraging this feature, allowing external actors to send emails that appear to originate from legitimate internal addresses, effectively bypassing traditional phishing filters. This exploit requires no login or credentials, as the smart host accepts emails from any external source as long as the recipient is internal to the tenant, and the "From" address can be easily spoofed. Second, eight new vulnerabilities have been discovered in over 748 printer models from five manufacturers, with 689 specifically affecting Brother printers. While seven of these vulnerabilities can be patched via firmware updates, one critical vulnerability (CVE-2024-51978, CVSS 9.8) is unfixable through firmware alone, requiring a complete change in the manufacturing process for new models. This flaw allows remote unauthenticated attackers to generate default administrator passwords by transforming the device's unique serial number. This poses a significant risk, as attackers could reconfigure printers or install malicious software to exfiltrate sensitive printed documents. Finally, a new set of vulnerabilities affecting Citrix NetScaler ADC and Gateway products, dubbed "CitrixBleed 2" (including CVE-2025-5777), has emerged. This vulnerability exploits out-of-bounds memory reads to steal authentication tokens, bypass multi-factor authentication (MFA), and hijack user sessions. Despite Citrix's initial public statements that these vulnerabilities had not been exploited in the wild, ReliaQuest assesses with medium confidence that attackers are actively leveraging CitrixBleed 2 for initial access to targeted environments. Citrix has also been observed to be slowly changing the public information regarding these CVEs. Users are strongly advised to update their Citrix instances immediately, especially since some affected versions are now End-of-Life.

### Microsoft 365 Direct Send Spoofing

- Varonis Threat Labs discovered a phishing campaign exploiting M365's Direct Send feature since May 2025
- This feature allows internal devices to send emails without authentication, bypassing phishing filters
- Attackers use PowerShell to send spoofed emails from external IPs that appear internal, requiring no login or credentials
- The smart host accepts emails from any external source if the recipient is internal, and the "From" address can be spoofed.

### Unfixable Printer Vulnerability

- Eight new vulnerabilities affect over 748 printer models across five manufacturers, with 689 being Brother printers
- Contact about these vulnerabilities began in May 2024, with CVSS scores ranging from 5.3 to a critical 9.8
- The critical CVE-2024-51978 allows remote unauthenticated attackers to generate default administrator passwords by transforming the device's unique serial number
- This critical vulnerability cannot be fully remediated by firmware and requires a manufacturing process change for new models, while older models have only a workaround
- Printer vulnerabilities are serious as attackers can gain admin access to reconfigure devices or install malware to steal sensitive print data.

### CitrixBleed2? Fast 2 Furious

- Citrix NetScaler Gateway and ADC products were affected by a buffer overflow (CVE-2023-4966, "CitrixBleed") in 2023, allowing MFA bypass and user session hijacking
- A new set of vulnerabilities, including CVE-2025-5777 ("CitrixBleed 2"), affects the same products
- CVE-2025-5777 uses out-of-bounds memory reads to steal tokens and authentication data, bypassing MFA and hijacking user sessions
- While Citrix initially stated no public exploitation, ReliaQuest assesses with medium confidence that attackers are actively exploiting CitrixBleed 2 for initial access
- Citrix has been observed changing CVE information over time, and users are urged to update affected NetScaler instances, especially those that are End-of-Life.

![Screenshot at 0:11: Text overlay "Microsoft 365 Direct Send Spoofing" with the host speaking.](https://ss.rapidrecap.app/screens/aeLfTB5K72g/00-00-11.png)
![Screenshot at 0:21: Varonis Threat Labs article title "Ongoing Campaign Abuses Microsoft 365's Direct Send to Deliver Phishing Emails".](https://ss.rapidrecap.app/screens/aeLfTB5K72g/00-00-21.png)
![Screenshot at 0:48: Text overlay explaining "How attackers exploit Direct Send" with a PowerShell command example and bullet points.](https://ss.rapidrecap.app/screens/aeLfTB5K72g/00-00-48.png)
![Screenshot at 1:21: Text overlay "Unfixable Printer Vulnerability Found" with the host speaking.](https://ss.rapidrecap.app/screens/aeLfTB5K72g/00-01-21.png)
![Screenshot at 1:50: Text overlay detailing CVE-2024-51978: "The authentication bypass vulnerability CVE-2024-51978 allows a remote unauthenticated attacker to generate the target device's default administrator password. The default password is generated during the manufacturing process by transforming the device's unique serial number into the default password."](https://ss.rapidrecap.app/screens/aeLfTB5K72g/00-01-50.png)
![Screenshot at 2:19: Text overlay with a quote from Rapid7 about the unfixable printer vulnerability.](https://ss.rapidrecap.app/screens/aeLfTB5K72g/00-02-19.png)
![Screenshot at 3:16: Text overlay "CitrixBleed2? Fast 2 Furious" with the host speaking.](https://ss.rapidrecap.app/screens/aeLfTB5K72g/00-03-16.png)
![Screenshot at 3:38: Citrix security bulletin for CVE-2025-5349 and CVE-2025-5777, showing affected versions.](https://ss.rapidrecap.app/screens/aeLfTB5K72g/00-03-38.png)
![Screenshot at 4:20: Text overlay with a quote from ReliaQuest about CitrixBleed 2 exploitation.](https://ss.rapidrecap.app/screens/aeLfTB5K72g/00-04-20.png)
