81 Million Login Attempts: Massive Password Spray Campaign Bypasses MFA to Compromise Azure and Microsoft 365 Accounts
A massive automated campaign made 81 million login attempts against Microsoft 365 and Azure CLI accounts between June 12 and June 26, 2026, successfully compromising 78 accounts across 64 organizations by exploiting the legacy OAuth ROPC flow to bypass MFA. Huntress researchers have traced the attack traffic to infrastructure linked to China and are urging organizations to audit their Conditional Access Policy configurations immediately.
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.