Dettaglio notizia

Data 01/07/2026
Titolo Azure CLI Password Spray Bypassed Conditional Access in Microsoft 365 Accounts
Contesto A large-scale password spray campaign targeted Microsoft 365 environments through Azure CLI logins, generating more than 81 million authentication attempts and compromising at least 78 accounts across 64 organizations, according to Huntress. The attackers abused the deprecated OAuth Resource Owner Password Credentials (ROPC) flow to validate stolen username-password pairs and obtain user-delegated tokens, relying on previously breached credentials that had not been rotated.

The activity was observed between mid and late June and in some cases succeeded even where MFA and Conditional Access were enabled, because policies were misconfigured or did not fully cover Azure CLI ROPC authentication. Huntress said most attempts originated from the IPv6 range 2a0a:d683::/32, associated with LSHIY LLC (AS32167), and reported a more than 155-fold increase in credential-spray volume across its customer base over six months. Defenders were urged to enforce MFA for all users, cloud apps, and client app types, and to restrict Azure CLI access for non-admin users.
Fonte https://mallory.ai/stories/019f1c4c-8e4d-7048-ad8e-fdac1af514fc
Discussione? Parliamone sul Forum