Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Microsoft Azure’s CLI target of automated password spray attacks

Threat actors are conducting automated password spray attacks targeting Microsoft Azure's CLI, exploiting the legacy Resource Owner Password Credentials (ROPC) flow to bypass interactive authentication layers where MFA is typically enforced. The attacks, observed by Huntress between June 12-26, 2026, involved over 81 million login attempts and compromised 78 user accounts, highlighting a significant gap where MFA policies were assumed to be complete but were not applied to all authentication pathways. To mitigate this, security teams must enforce MFA for all users, applications, and client types while restricting legacy auth flows like ROPC and access to tools like Azure CLI for non-administrative users.
Read Full Article →

Identity , SSO/MFA Microsoft Azure’s CLI target of automated password spray attacks July 1, 2026 Share By Steve Zurier (Adobe Stock) A massive, ongoing series of automated password spray attacks were observed targeting Microsoft Azure’s command line interface (CLI), according to researchers at Huntress. Huntress reported in a June 30 blog post that between June 12 and June 26, its team saw undetermined threat actors compromise 78 user accounts across 64 organizations. Over this 14-day window, the researchers said they saw over 81 million login attempts, the majority of which originated from AS32167, an autonomous system that’s linked back to internet infrastructure provider LSHIY, LLC. Security pros were concerned because in its ongoing research Huntress observed a 155-fold increase in credential spray volume over the past six months, and security teams have to take note. “Attackers aren't finding new ways in,” said Shane Barney, chief information security officer at Keeper Security. “They're systematically working through every authentication pathway organizations forgot to account for, testing previously breached credentials until something gives. Most security leaders have seen this dynamic before. The problem isn’t multi-factor authentication ( MFA ), it’s that policies get written once, scoped to the most visible applications and never revisited, while the authentication environment around them keeps growing.” Barney explained that the resource owner password credentials (ROPC) flow exploited in this campaign is a legacy protocol that routes credentials directly to the token endpoint, entirely bypassing the interactive authentication layer where most MFA policies are enforced. “The organizations caught up in this campaign weren't without security controls,” said Barney. “They were operating under the assumption that their MFA coverage was complete when it wasn't. Closing those gaps requires treating MFA as a living control rather than a compliance checkbox. Coverage must extend to all users, all cloud applications and all client authentication types, with legacy flows like ROPC restricted for non-administrative users entirely.” Roy Katmor, co-founder and CEO of Orchid Security, added that MFA being enabled and MFA actually firing are two different things — and attackers have figured out how to land in the gap between them. “Authentication tells you someone got in, but it tells you nothing about what they do next,” said Katmor. "Defenders spend enormous effort proving an identity is who it claims to be at login, and almost none watching how it behaves afterward. That's the half of the problem attackers are now living in." Here are four tips from Katmor on how teams can mitigate these type of identity-based credential attacks: Close the auth-flow gaps: Enforce MFA for all users, all cloud apps, and all relevant client app types, not just admin portals or specific groups. Restrict Azure CLI and similar clients: Most users do not need Azure CLI access. Treat password hygiene as live exposure: Rotate credentials known to appear in breaches, block common and compromised passwords and eliminate password reuse. Move from identity and access management control to application-layer identity visibility: These attacks succeed because identity controls are assumed to apply everywhere, but in reality they often apply unevenly across flows, apps, clients, local accounts, service accounts, and delegated access paths. Teams need to know which identities exist, where they authenticate, what apps they can reach, which flows bypass expected controls, and whether each application can produce a defensible audit trail. Steve Zurier Related Privacy WhatsApp introduces usernames to enhance user privacy SC Staff June 30, 2026 The new username functionality enables users to set a unique handle and share that instead of their personal phone number when initiating conversations. Privacy Supreme Court limits geofence search warrants, bolsters privacy rights SC Staff June 29, 2026 In a 6-3 decision, the Supreme Court ruled that the Fourth Amendment's protection against unreasonable searches and seizures applies to location data collected by companies like Google. Privacy ATF cancels contract for ad-surveillance technology after privacy concerns SC Staff June 26, 2026 As outlined in CyberScoop, the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has canceled a contract with Penlink that utilized ad-surveillance technologies to track Americans' locations. Related Events Cybercast The identity evolution that enables AI confidence Tue Aug 11 Cybercast IAM for MSSPs: Real-World Deployments On-Demand Event Cybercast Privilege risk is in the lifecycle: A CISO discussion on modernizing identity control On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Basic Authentication Biometrics Certificate-Based Authentication Challenge-Handshake Authentication Protocol (CHAP) Digest Authentication Digital Certificate Discretionary Access Control (DAC) False Rejects You can skip this ad in 5 seconds

Share this article