Identity Password spraying attacks surge 155x, exploiting legacy authentication flaws August 20, 2026 Share By SC Staff Credit: Adobe Stock Images Password spraying attacks have seen a significant 155x increase in the first half of 2026, driven by a novel campaign targeting Microsoft's Azure CLI, according to Huntress. This surge highlights the exploitation of outdated authentication methods, even in environments with modern security measures, with further coverage provided by Bleeping Computer. The campaign, originating from an IPv6 range provided by LSHIY LLC, leveraged reused credentials and the legacy Resource Owner Password Credentials (ROPC) OAuth grant, which bypasses multi-factor authentication (MFA) and single sign-on (SSO). Attackers used valid usernames and previously breached passwords, attempting them against accounts to gain unauthorized access. While many compromised organizations had MFA implemented, their Conditional Access Policies (CAPs) were not configured to cover the ROPC flow, leaving a critical vulnerability. The attackers' ability to quickly switch IP ranges and providers, including FranTech and 3xK Tech, made traditional IP-based blocking ineffective. Huntress observed that the attacks were not industry-specific but exploited gaps in password controls and MFA policies, affecting 23 businesses, eight of which lacked MFA entirely. The findings underscore the need for organizations to meticulously review and scope their MFA policies to cover all sign-in methods and user groups. Source: Bleeping Computer SC Staff Related AI/ML Agentic IAM: How to secure and manage AI agent identities Ping Security August 20, 2026 Explore how Agentic Identity and Access Management (IAM) helps organizations securely manage AI agents as governed non-human identities. Learn how identity, authentication, dynamic authorization, secure delegation, and real-time oversight can enable organizations to safely adopt and scale agentic AI while maintaining security and accountability. Privacy Brazil’s data authority orders halt to facial recognition in Paraná schools SC Staff August 20, 2026 The ANPD cited a failure by the Paraná State Department of Education to demonstrate an adequate legal basis for processing sensitive biometric data, nor sufficient guarantees of security and governance. Identity A ‘kill switch’ law only makes sense for a worst-case scenario Garrett Gross August 19, 2026 Congress wants an AI ‘kill switch’ – but we really need identity-based access. Related Events Cybercast Building the Future of Trust in the AI Era & AI-First Headless Identity Let’s You Build with AI Wed Sep 2 Cybercast The Future of Identity: Powering Trust in the AI Era & Fireside Chat with LPL Financial Tue Sep 1 Cybercast The identity evolution that enables AI confidence On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Basic Authentication Biometrics Certificate-Based Authentication Challenge-Handshake Authentication Protocol (CHAP) Digest Authentication Digital Certificate Discretionary Access Control (DAC) You can skip this ad in 5 seconds