EPISODE · Jul 1, 2026 · 0 MIN
Massive Password Spray Campaign Targeting Azure CLI
from Security Stuff · host Trace3
Cybersecurity firm Huntress is warning about a massive password spray campaign targeting Microsoft 365 environments through the Azure CLI. Over a nine-day period in June, attackers launched more than 81 million login attempts, successfully compromising 78 user accounts across 64 organizations by exploiting a weakness in the OAuth ROPC authentication flow that can bypass multi-factor authentication if not properly configured. The attacks, which originated from infrastructure linked to a Chinese internet hosting provider, highlight the critical importance of implementing MFA policies that cover all authentication flows and cloud applications.
Embed this episode
NOW PLAYING
Massive Password Spray Campaign Targeting Azure CLI
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.