Cyber security researchers Patrik Fehrenbach and Behrouz Sadeghipour discovered that an attacker can register any unused (not previously registered with Google apps service) domain, example: mynewco.com. The vulnerability in Google Apps for Work could be exploited to send emails by abusing any website’s domain name and run phishing campaign on the victims behalf. Google immediately patched the flaw but the experts explained that the fix is just partial. An attacker is still able to access Send Sign in Instructions for unverified domains, but this time via [email protected], instead of the custom email address.”]
Source: http://securityaffairs.co/wordpress/34625/hacking/google-apps-flaw-phishing.html

