Are they spoofing SPF, DMARC and DKIM DNS entries? Those entries are the ones that are currently determining if something is fraudulent or not and if those checks fail, most web filters will stop the message for admin review.
There's prob some trick that makes outlook believe the email was signed in a way that supercedes all other checks. Who knows what edgecase pajeets didn't think to check
Edit: Microsoft prob hasn't patched it because the (((feds))) are currently using the exploit for psyops or it was a feature written for them in the first place
CDK (dealership management software) was ransomewared today...so the feds are being productive.
(post is archived)