
Security researchers have discovered a new technique that allows threat actors to send spoofed emails with false addresses. They can use this technique to deliver highly targeted phishing emails, while avoiding being spotted by email security solutions.
Timo Longin, a senior security consultant at SEC Consult, published a report on the technique, which he called SMTP smuggling.