Episode
Direct Send Exploitation & URL Rewrite Attacks: What Security Teams Must Know
- Published
- Aug 26, 2025
- Duration seconds
- 2585
- Processing state
not_requested
Actions
POST https://stenobird.com/v1/public/podcasts/discarded-tales-from-the-threat-research-trenches-5154469/episodes/direct-send-exploitation-url-rewrite-attacks-what-security-teams-must-know/transcription-requests
Idempotently request low-priority transcript generation for this episode.GET https://stenobird.com/podcast/discarded-tales-from-the-threat-research-trenches-5154469/direct-send-exploitation-url-rewrite-attacks-what-security-teams-must-know.md
Read the agent-friendly Markdown representation of this episode resource.
Summary
Send us fan mail! Hello to all our Cyber Squirrels! In this extra-packed episode of Discarded, host Selena Larson welcomes Proofpoint Principal Research Engineer Jason Ford for his first appearance on the show. Together, they dive into two resurging email attack techniques—Microsoft 365 Direct Send abuse and URL rewrite abuse—and why defending against them requires more than just traditional email security. Jason explains what Direct Send is, why attackers exploit this legacy feature, and how...