A large-scale automated password spray attack targeted Microsoft 365 accounts, with attackers making 81 million login attempts against Huntress customers between June 12–26, successfully compromising at least 78 accounts. The attack originated from a single IPv6 address range controlled by LSHIY LLC and exploited the OAuth ROPC flow using previously exposed credentials. Success was enabled by misconfigured MFA policies — some organizations enforced MFA only for specific apps or user groups rather than all cloud apps, leaving gaps that attackers exploited via Azure CLI logins.

2m read timeFrom csoonline.com
Post cover image
109 Impressions