# Direct Send Exploitation & URL Rewrite Attacks: What Security Teams Must Know Page: https://stenobird.com/podcast/discarded-tales-from-the-threat-research-trenches-5154469/direct-send-exploitation-url-rewrite-attacks-what-security-teams-must-know Text version: https://stenobird.com/podcast/discarded-tales-from-the-threat-research-trenches-5154469/direct-send-exploitation-url-rewrite-attacks-what-security-teams-must-know.md Podcast: [DISCARDED: Tales From the Threat Research Trenches](https://stenobird.com/podcast/discarded-tales-from-the-threat-research-trenches-5154469) Published: 2025-08-26T08:00:00+00:00 Episode link: https://www.buzzsprout.com/2445401/episodes/17731824-direct-send-exploitation-url-rewrite-attacks-what-security-teams-must-know.mp3 Audio file: https://www.buzzsprout.com/2445401/episodes/17731824-direct-send-exploitation-url-rewrite-attacks-what-security-teams-must-know.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/discarded-tales-from-the-threat-research-trenches-5154469/episodes/direct-send-exploitation-url-rewrite-attacks-what-security-teams-must-know Duration seconds: 2585 ## Resource Send us fan mail! Hello to all our Cyber Squirrels! In this extra-packed episode of Discarded, host Selena Larson welcomes Proofpoint Principal Research Engineer Jason Ford for his first appearance on the show. Together, they dive into two resurging email attack techniques—Microsoft 365 Direct Send abuse and URL rewrite abuse—and why defending against them requires more than just traditional email security. Jason explains what Direct Send is, why attackers exploit this legacy feature, and how... ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/discarded-tales-from-the-threat-research-trenches-5154469/episodes/direct-send-exploitation-url-rewrite-attacks-what-security-teams-must-know/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/discarded-tales-from-the-threat-research-trenches-5154469/direct-send-exploitation-url-rewrite-attacks-what-security-teams-must-know.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.