Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Massive password spray attack targets Azure CLI, bypasses MFA

A large-scale password spray attack targeting Microsoft Azure CLI exploited the deprecated Resource Owner Password Credentials (ROPC) OAuth flow to bypass Conditional Access policies and MFA, making over 81 million login attempts and compromising at least 78 accounts. The attack succeeded by leveraging compromised password lists and targeting organizations where MFA was not universally enforced for all cloud apps or client types. This incident underscores the critical need to disable legacy authentication protocols like ROPC and to ensure Conditional Access policies are comprehensively configured to cover all application and client scenarios.
Read Full Article →

Identity Massive password spray attack targets Azure CLI, bypasses MFA July 2, 2026 Share By SC Staff (Adobe Stock) Coverage from The Hacker News indicates a large-scale, automated password spray attack is targeting Microsoft's Azure command-line interface (CLI), successfully compromising dozens of accounts. Huntress reports that the activity, originating from an IPv6 address range controlled by LSHIY LLC, has been ongoing since at least June 12. The attack, which leveraged a deprecated OAuth flow called Resource Owner Password Credentials (ROPC), made over 81 million login attempts between June 12 and June 26, compromising at least 78 Microsoft accounts across 64 organizations. Despite many targeted organizations having Conditional Access policies enabled, the ROPC flow allowed attackers to bypass these protections. ROPC is a legacy OAuth 2.0 grant type where users directly provide credentials to an application, a method Microsoft advises against due to its incompatibility with multi-factor authentication (MFA). The attackers exploited compromised password lists, targeting accounts indiscriminately across industries. While some organizations had MFA configured, it was not enforced for all cloud apps or client types, allowing the ROPC flow to succeed. Eight impacted businesses reportedly had no MFA policy at all. The attack highlights weaknesses in improperly configured Conditional Access policies, particularly how legacy protocols can circumvent security measures if not properly addressed. Source: The Hacker News SC Staff Related Identity Microsoft Teams enhances bot protection with human verification SC Staff July 1, 2026 The new technology acts like a security guard, requiring a human user to verify the identity of bots in the meeting lobby before the session begins. AI/ML The identity crisis at the heart of AI regulation Aaron Painter July 1, 2026 AI regulation may force the internet to solve its long-standing identity problem. Identity Microsoft Azure’s CLI target of automated password spray attacks Steve Zurier July 1, 2026 Huntress researchers saw 78 user accounts compromised across 64 organizations. Related Events Cybercast The identity evolution that enables AI confidence Tue Aug 11 Cybercast IAM for MSSPs: Real-World Deployments On-Demand Event Cybercast Privilege risk is in the lifecycle: A CISO discussion on modernizing identity control On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Basic Authentication Biometrics Certificate-Based Authentication Challenge-Handshake Authentication Protocol (CHAP) Digest Authentication Digital Certificate Discretionary Access Control (DAC) You can skip this ad in 5 seconds

Share this article