
Source: Bleeping Computer
Summary
A security vulnerability in Microsoft’s email system allows spammers and scammers to send emails from a legitimate Microsoft email address, typically used for sending genuine account alerts. The loophole enables malicious actors to trick users into divulging sensitive information. The issue was discovered by a security researcher who reported it to Microsoft. The company has acknowledged the problem and is working on a fix.
Our Reading
The launch follows a familiar script.
Microsoft’s email system has a security vulnerability that allows spammers to send emails from a legitimate address. Because what could possibly go wrong with that? The loophole is used for sending genuine account alerts, which is just what you want – more email from Microsoft. The issue was discovered by a security researcher, because of course it was. Microsoft is working on a fix, which will probably be ready just in time for the next vulnerability to be discovered.
Author: Evan Null









