How a Single Misconfigured Email Record Let Us Send Emails as the CEO — A Real Penetration Test
During an authorized penetration test, we sent an email as the company CEO to their entire finance team. Office 365 accepted it without warning. The email looked perfectly legitimate. The fix took 15 minutes — but the company had been exposed for years.














