Feeds.4Sysops Massive Password Spray Attack Targets Microsoft 365 Accounts
Article Content
- •Over 81 million login attempts were made against Microsoft 365 accounts in a two-week period.
- •The attack exploited misconfigured Conditional Access policies, allowing bypass of MFA.
- •78 Microsoft accounts were compromised across 64 organizations during the campaign.
A significant automated password spray attack has targeted Microsoft 365 environments, generating over 81 million login attempts between June 12 and June 26, 2026. The attack, attributed to a threat actor using an IPv6 address range controlled by LSHIY LLC, successfully compromised 78 Microsoft accounts across 64 organizations. Attackers exploited the Azure command-line interface (CLI) using valid username and password combinations from previous breaches. Despite many organizations having multi-factor authentication (MFA) in place, misconfigurations in Conditional Access policies allowed the attackers to bypass MFA using the Resource Owner Password Credentials (ROPC) OAuth mechanism. Huntress, a cybersecurity firm, reported a 155-fold increase in password spray attacks over the past six months. The attack highlights vulnerabilities in existing security configurations, particularly regarding legacy authentication methods.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (11)
Following this threat?
Track Azure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…