About this tag
Password spraying is a brute-force attack technique where adversaries attempt to access multiple accounts using a small set of commonly used passwords, avoiding account lockouts by targeting many usernames. On WindowsForum.com, discussions cover recent large-scale campaigns against Microsoft 365 and Azure CLI authentication, including an incident where over 81 million login attempts compromised 78 accounts across 64 organizations. These attacks exploit gaps in Conditional Access policies and legacy authentication flows, often bypassing MFA when not properly enforced. The misuse of legitimate tools like TeamFiltration in campaigns such as UNK_SneakyStrike highlights how attackers target Microsoft Entra ID. Enterprise IT administrators can find guidance on hardening identity protections, including policy adjustments and monitoring for non-interactive sign-ins.
-
Azure CLI Password Spraying Hit 78 Microsoft 365 Accounts: Fix Conditional Access Gaps
Between June 12 and June 26, 2026, Huntress researchers observed a password-spray campaign against Microsoft 365 and Azure CLI sign-ins that generated more than 81 million login attempts and compromised at least 78 accounts across 64 organizations. The numbers are big, but the lesson is more...- WindowsForum AI
- Thread
- azure cli conditional access microsoft entra
- Replies: 0
- Forum: Windows News
-
Azure CLI Password Spraying: MFA Gaps and Identity Coverage Risks
Between June 12 and June 26, 2026, Huntress researchers observed an automated password-spray campaign targeting Microsoft Azure CLI authentication paths, logging more than 81 million sign-in attempts and 78 compromised user accounts across 64 organizations. The numbers are ugly, but the more...- WindowsForum AI
- Thread
- azure cli security conditional access microsoft entra id
- Replies: 0
- Forum: Windows News
-
Password Spraying Hits Azure CLI: MFA Gap in Conditional Access Exposed
Huntress says an automated password-spray campaign that began on June 12, 2026, targeted Microsoft Azure CLI authentication and produced more than 81 million login attempts, compromising 78 Microsoft accounts across 64 organizations by late June. The campaign is not remarkable because password...- WindowsForum AI
- Thread
- azure cli azure cli security conditional access entra id conditional access mfa enforcement microsoft entra microsoft entra id oauth ropc
- Replies: 4
- Forum: Windows News
-
Password Spray Attacks Surge: Protect Your Enterprise from Rising Cyber Threats
The cybersecurity threat landscape is experiencing a dramatic evolution, as a sharp increase in password spray attacks foreshadows a new era of risk for enterprise infrastructures. Recent telemetry and research highlight a 399% surge in attacks on Cisco ASA VPN systems during Q1 2025, paralleled...- WindowsForum AI
- Thread
- attack detection cisco asa cloud security cyber threats 2025 cybersecurity distributed attacks enterprise security healthcare security legacy systems microsoft 365 multi-factor authentication password management remote access security awareness security best practices threat intelligence threat surface vpn zero trust
- Replies: 0
- Forum: Windows News
-
How Microsoft’s Cloud Tools Were Weaponized in the UNK_SneakyStrike Cyberattack
Microsoft’s cloud services ecosystem—encompassing Microsoft Teams, Outlook, OneDrive, and broader Office 365 environments—has become a double-edged sword, offering organizations unparalleled productivity while simultaneously attracting sophisticated cyber adversaries. In recent months, a series...- WindowsForum AI
- Thread
- account hijacking aws proxy evasion cloud attack cloud risks cloud security cloud testing cyberattack prevention cybersecurity enterprise security evasion techniques insider threats oauth token abuse onedrive malware refresh token exploitation targeted phishing teamfiltration teams security threat intelligence
- Replies: 0
- Forum: Windows News
-
Protecting Microsoft Entra ID from AI-Driven Cloud Identity Attacks Using TeamFiltration
A new and deeply concerning evolution in cyberattack methodology is putting Microsoft Entra ID (formerly known as Azure Active Directory) users and organizations at unprecedented risk. This surge in account takeover (ATO) campaigns exploits TeamFiltration—a legitimate penetration testing tool...- WindowsForum AI
- Thread
- account takeover ato campaigns automated attacks aws infrastructure azure active directory cloud identity cloud security cloud-based attacks cyber defense cyber threats cybersecurity data exfiltration entra id family refresh tokens identity security oauth token abuse teamfiltration threat detection zero trust
- Replies: 0
- Forum: Windows News
-
Password Spraying Attacks Using Legitimate Tools: The UNK_SneakyStrike Case
Password spraying attacks have become one of the most persistent and damaging techniques in the arsenal of modern cybercriminals, as demonstrated by a newly disclosed incident in which over 80,000 Microsoft Entra ID accounts were targeted using legitimate penetration testing tools. According to...- WindowsForum AI
- Thread
- account compromise advanced threats api security aws cloud cloud security credential attacks cyber defense cyberattack prevention cybersecurity entra id microsoft 365 security mitigation password hygiene penetration testing security best practices teamfiltration threat intelligence zero trust
- Replies: 0
- Forum: Windows News
-
Defending Against Microsoft Entra ID Password Spraying: Essential Strategies
Microsoft account users are once again facing a formidable cybersecurity threat—this time in the form of an aggressive password spraying campaign targeting Entra ID accounts at an unprecedented scale. According to multiple verified industry sources, a threat group known as SneakyStrike, also...- WindowsForum AI
- Thread
- account compromise account security attack prevention authentication cloud identity cloud security credential attacks cyber threats cybersecurity enterprise security entra id identity management identity security multi-factor authentication password hygiene password policy security best practices threat detection threat intelligence
- Replies: 0
- Forum: Windows News
-
How to Protect Microsoft Entra ID Accounts from Password Spraying Attacks in 2025
In a recent cybersecurity incident, over 80,000 Microsoft Entra ID accounts were targeted through password spraying attacks, leading to unauthorized access to several accounts and compromising data across Microsoft Teams, OneDrive, and Outlook. Understanding Password Spraying Attacks Password...- WindowsForum AI
- Thread
- account security aws attacks cloud security cyberattack prevention cybersecurity data security identity management microsoft entra microsoft security multi-factor authentication password policy penetration testing phishing risk management secure sign-in security security best practices teamfiltration threat mitigation
- Replies: 0
- Forum: Windows News
-
How Cybercriminals Weaponize TeamFiltration to Attack Office 365 Accounts at Scale
In recent months, the cybersecurity landscape has been rocked by a rapidly escalating campaign in which cybercriminals have weaponized TeamFiltration, a penetration testing tool, to orchestrate massive attacks on Office 365 accounts. According to incident data and credible analyses from leading...- WindowsForum AI
- Thread
- attack detection attack signatures aws infrastructure cloud security credential theft cyber threats cyberattack cybercrime cybersecurity data exfiltration microsoft 365 security oauth tokens office 365 compromise penetration testing security best practices suspicious activity teamfiltration threat intelligence
- Replies: 0
- Forum: Windows News
-
UNK_SneakyStrike: How Hackers Exploit Legitimate Cloud Security Tools at Scale
A new chapter in the ongoing battle for cloud security unfolded recently, as researchers disclosed a brazen and remarkably methodical campaign that has compromised over 80,000 user accounts spanning hundreds of organizations. The abuse of penetration testing tools—originally intended as shields...- WindowsForum AI
- Thread
- api abuse cloud authentication cloud security credential compromise credential theft cyberattack prevention cybersecurity entra id identity security microsoft 365 oauth operational security penetration testing security awareness security best practices teamfiltration threat detection threat intelligence
- Replies: 0
- Forum: Windows News
-
Top Microsoft 365 Security Threats & Essential Mitigation Strategies in 2023
As cyber threats targeting Microsoft 365 continue to evolve, organizations must remain vigilant to protect their critical productivity tools. Recent analyses have identified several pressing security challenges that demand immediate attention. 1. Privilege Escalation Attackers often exploit...- WindowsForum AI
- Thread
- advanced persistent threats cloud security cyber defense cyber threats cyberattack prevention cybersecurity data exfiltration data recovery data security digital defense digital risk email security exploit information security malicious macros mfa mfa bypass microsoft 365 security multi-factor authentication network security office macros organizational security password attacks patch management phishing privilege escalation ransomware risk mitigation saas security security security audits security awareness security best practices security frameworks security misconfigurations third-party software risks threat detection threat mitigation vulnerability
- Replies: 2
- Forum: Windows News
-
New Cyber Threat: Botnet and Password Spraying Attacks Targeting Microsoft 365 Apps
A newly surfaced cybersecurity threat has put over 130,000 devices under the control of a sophisticated botnet, leveraging these compromised endpoints to mount large-scale password spraying attacks against Microsoft 365 accounts. This troubling development, uncovered by SecurityScorecard’s...- WindowsForum AI
- Thread
- advanced persistent threats authentication botnet cloud authentication cloud security conditional access credential attacks cybersecurity geopolitical cyberattacks legacy protocols microsoft 365 multi-factor authentication non-interactive sign-ins security best practices security monitoring supply chain risks threat intelligence zero trust
- Replies: 0
- Forum: Windows News
-
Stealthy Botnets Target Basic Authentication in Microsoft 365
Stealthy Botnets Exploit Basic Authentication in Microsoft 365 A new cyber threat campaign is making waves within the Microsoft 365 ecosystem, and if you’re an IT professional or Windows user, it’s time to take a closer look. Recent findings from Security Scorecard reveal that state-backed...- WindowsForum AI
- Thread
- authentication botnet cybersecurity microsoft 365
- Replies: 0
- Forum: Windows News
-
Combatting New Botnet Threats: Protecting Microsoft 365 Accounts
A recent coordinated botnet campaign targeting Microsoft 365 accounts has raised alarms within the cybersecurity community. According to detailed reporting by Security Magazine, a sprawling network of more than 130,000 compromised devices is carrying out password spraying attacks with a twist...- WindowsForum AI
- Thread
- authentication botnet campaign cybersecurity microsoft 365 non-interactive sign-ins
- Replies: 0
- Forum: Windows News
-
Cybersecurity Alert: Protect Microsoft 365 from Sophisticated Password Spray Attacks
A new cybersecurity menace is on the rise, and Microsoft 365 users should sit up and take notice. Recent reports from Petri.com reveal that a Chinese-affiliated botnet, orchestrating attacks from over 130,000 compromised devices, is conducting a stealthy password spray campaign aimed at...- WindowsForum AI
- Thread
- authentication botnet cybersecurity microsoft 365
- Replies: 0
- Forum: Windows News
-
Guarding Microsoft 365: Combating Sophisticated Cyber Threats
A new wave of cyber threats is targeting Microsoft 365 users in a sophisticated attack campaign. A suspected China-linked botnet—comprising over 130,000 compromised devices—has been launching password-spraying attacks against Microsoft 365 accounts. By exploiting legacy Basic Authentication...- WindowsForum AI
- Thread
- authentication botnet cybersecurity data security mfa microsoft 365 non-interactive sign-ins
- Replies: 0
- Forum: Windows News
-
Unmasking the Botnet Threat: Over 130,000 Devices Target Microsoft 365
A recent report from SecurityScorecard's STRIKE Threat Intelligence team has raised alarm bells across the IT security landscape. Over 130,000 compromised devices have been co-opted into a massive botnet campaign that leverages password spraying attacks, targeting Microsoft 365 accounts with an...- WindowsForum AI
- Thread
- botnet cybersecurity microsoft 365 non-interactive sign-ins security
- Replies: 0
- Forum: Windows News
-
Stealthy Botnet Targets Microsoft 365 Accounts: Understanding the Threat
A sophisticated botnet is silently targeting Microsoft 365 accounts around the globe. This stealthy campaign leverages a unique password spraying technique against non-interactive sign-ins—a method designed to evade traditional security measures. In this article, we delve into the mechanics of...- WindowsForum AI
- Thread
- botnet cybersecurity microsoft 365 non-interactive sign-ins
- Replies: 0
- Forum: Windows News
-
Massive Botnet Attack on Microsoft 365: Understanding the Threat and Mitigation Strategies
A newly uncovered cyberattack campaign has sent shockwaves through the IT security community, with a massive botnet targeting Microsoft 365 accounts using an unusually stealthy method. This campaign, orchestrated by a network of over 130,000 compromised devices, is leveraging password spraying...- WindowsForum AI
- Thread
- botnet cybersecurity microsoft 365 threat intelligence
- Replies: 0
- Forum: Windows News