FeedMalwareHackers target Microsoft 365 accounts with 81 million login ...
MalwareBleeping Computer
8.5CRITICAL

Hackers target Microsoft 365 accounts with 81 million login attempts

📅 1 July 2026 at 16:38 UTC📰 Bleeping ComputerView original source ↗
Hackers target Microsoft 365 accounts with 81 million login attempts

An aggressive password-spraying campaign targeting Microsoft 365 environments generated more than 81 million login attempts over a two-week period. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

A sophisticated password-spraying campaign targeting Microsoft 365 environments resulted in over 81 million login attempts, exploiting insecure Conditional Access policies and ROPC OAuth mechanism to bypass multi-factor authentication.

⚙️Technical Details
Affected Systems
Microsoft Azure CLI
Attack Vectors
Resource Owner Password Credentials (ROPC) OAuth mechanism
💥Impact Assessment
Severity: high
Who Is at Risk
64 organizations with compromised Microsoft accounts, including managed cybersecurity company Huntress customers
🛡️Recommended Actions
1Implement Conditional Access policies to cover all cloud apps and enforce MFA for all users
2Configure MFA to require authentication from all locations, not just untrusted ones
3Regularly review and update MFA policies to prevent similar exploitation
📦Affected Products
Software: Microsoft Azure CLI

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed