Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 16, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 16, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 16, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 16, 2025

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025

      Minecraft licensing robbed us of this controversial NFL schedule release video

      May 16, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The power of generators

      May 16, 2025
      Recent

      The power of generators

      May 16, 2025

      Simplify Factory Associations with Laravel’s UseFactory Attribute

      May 16, 2025

      This Week in Laravel: React Native, PhpStorm Junie, and more

      May 16, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025
      Recent

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Researchers Bypass Microsoft 365 Anti-Phishing Measures By Manipulating First Contact Safety Tip

    Researchers Bypass Microsoft 365 Anti-Phishing Measures By Manipulating First Contact Safety Tip

    August 7, 2024

    While Microsoft 365 (formerly Office 365) has implemented various anti-phishing measures to protect its users, researchers have found a bypass for the First Contact Safety Tip feature within the application.

    The researchers demonstrated how these safeguards can be circumvented by determined attackers with sufficient knowledge of CSS.

    Manipulating Microsoft 365 Anti-Phishing First Contact Safety Tip

    One of the key anti-phishing features in Microsoft 365 is the First Contact Safety Tip, which alerts users when they receive an email from an address they don’t typically communicate with. However, researchers have discovered a way to bypass this measure by manipulating the email’s HTML code.

    Source: certitude.consulting

    The vulnerability lies in the fact that the safety tip can be hidden from the user by altering the HTML code of the email using CSS style tags. This can be done by changing the background and font colors to white, effectively rendering the safety tip invisible to the user.

    By using strategic CSS styling, researchers from Certitude were able to effectively “hide” the First Contact Safety Tip from the email’s recipient. This was achieved by changing the background and font colors to white, effectively rendering the alert invisible to the user.

    Source: certitude.consulting

    Building upon their findings, the researchers took their exploration of Microsoft 365‘s anti-phishing defenses a step further. They were able to spoof the icons that Outlook uses to allow users to recognize emails that are encrypted and/or signed, potentially deceiving even more attentive users due to the level of similarity.

    Responsible Disclosure and Microsoft’s Response

    After developing their proof of concept and preparing an advisory, the researchers responsibly disclosed the issues to Microsoft through the Microsoft Researcher Portal (MSRC). While Microsoft acknowledged the validity of the findings, they chose not to address the vulnerabilities immediately, citing that the issues were “mainly applicable for phishing attacks” and that they would be marked for future review as an opportunity to improve their products.
    We determined your finding is valid but does not meet our bar for immediate servicing considering this is mainly applicable for phishing attacks. However, we have still marked your finding for future review as an opportunity to improve our products. – Microsoft MSRC, 14.02.2024
    The discovery of the First Contact Safety Tip bypass vulnerability serves as a fine example that that no security system is foolproof, and users should always take adequate precaution against phishing attacks.

    Anti-phishing measures at the individual/employee level can include maintaining caution against emails from unfamiliar senders, checking for unusual formatting or spelling mistakes, and verifying the authenticity of emails before taking any action.

    At the organizational level, security teams for enterprises that rely on Microsoft 365 can consider implementing additional security measures to complement existing anti-phishing features.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleINTERPOL Authorities Recover Over $40 Million from International Email Scam
    Next Article AWS Vulnerabilities Revealed by Researchers at Black Hat Conference

    Related Posts

    Machine Learning

    LLMs Struggle with Real Conversations: Microsoft and Salesforce Researchers Reveal a 39% Performance Drop in Multi-Turn Underspecified Tasks

    May 17, 2025
    Machine Learning

    This AI paper from DeepSeek-AI Explores How DeepSeek-V3 Delivers High-Performance Language Modeling by Minimizing Hardware Overhead and Maximizing Computational Efficiency

    May 17, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    The Dumbest Thing in Security This Week: Worst. Phishing. Test. EVER.

    Development

    Bitrix24 Supernova Release: Igniting Exponential Growth with Increased Efficiency and Productivity

    Development

    Go VIRAL on YouTube in 48 Hours: Srinidhi Ranganathan and BookSpotz Will Explode Your Product to Fame with 10 Lakhs Rupees!

    Artificial Intelligence

    A Beginner’s Guide to Setting Up a Project in Laravel

    Development

    Highlights

    Development

    Tired of Flaky Tests? How Playwright Ensures Reliable and Scalable Automation

    February 13, 2025

    Flaky tests are a nightmare for QA teams, causing unreliable results and slowing down releases. Playwright Automation changes the game by eliminating test flakiness. Read this blog dives to know how Playwright does it.
    The post Tired of Flaky Tests? How Playwright Ensures Reliable and Scalable Automation first appeared on TestingXperts.

    Total.js UI Builder: How to upload files?

    December 20, 2024

    How to Fix ERROR_OBJECT_NAME_EXISTS in Windows

    February 18, 2025

    StarCalendar – full-featured international calendar

    June 28, 2024
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.