InfoSec News Nuggets – 09/14/2026
Brief
Hackers Favor US Eastern Business Hours in M365 Phishing Campaign
KnowBe4 Threat Lab observed a phishing campaign abusing Microsoft 365’s Direct Send feature — a legitimate mechanism meant for printers and legacy devices to send mail without a dedicated account — identifying nearly 29,800 confirmed phishing emails across July and August that followed a distinctly human, business-hours delivery pattern peaking around 2pm US Eastern time on Mondays and Tuesdays.
Because Direct Send lets a message appear to originate from an organization’s own domain without ever compromising an employee account, the campaign can bypass the usual assumption that internal-looking mail is safe, with roughly 35% of observed messages carrying malicious attachments and thousands using mismatched reply-to addresses to redirect victim responses.
