HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Password Spraying Attacks Surge 155×, Exploiting MFA Gaps in Azure CLI and Legacy OAuth Flow

Huntress reported a 155‑fold rise in password‑spraying attempts that exploited a legacy OAuth grant (ROPC) to bypass MFA on Azure CLI. The campaign compromised 78 accounts, highlighting a compliance gap in access‑control policies that SOC 2 audits must evidence.

LiveThreat™ Intelligence · 📅 August 20, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
4 recommended
📰
Source
bleepingcomputer.com

Password Spraying Attacks Surge 155×, Exploiting MFA Gaps in Azure CLI and Legacy OAuth Flow

What Happened — Huntress observed a 155‑fold increase in password‑spraying attempts in H1 2026, with a single campaign targeting Microsoft Azure CLI and the deprecated Resource Owner Password Credentials (ROPC) OAuth grant. In a two‑week window the attackers made more than 81 million login attempts, resulting in 78 compromised accounts that bypassed MFA because the Conditional Access Policy did not cover the ROPC flow.

Why It Matters for Compliance & Audit Readiness

  • The scenario maps directly to SOC 2 CC6.1 (Logical Access) and CC6.2 (User Management) – controls that require documented MFA coverage for all authentication flows.
  • Continuous monitoring of authentication logs and evidence of policy enforcement are essential audit artifacts to demonstrate that MFA gaps have been remediated.
  • The incident underscores the need for a defensible credential‑rotation process and proof that legacy authentication methods are disabled or tightly controlled.

Who Is Affected – Cloud‑infrastructure providers, SaaS platforms, and any organization that relies on Azure CLI or other OAuth‑based automation tools (technology, financial services, healthcare, and professional services).

Recommended Actions

  • Review and extend Conditional Access Policies to include all OAuth grant types, especially ROPC.
  • Disable legacy authentication flows (ROPC) where not required, or enforce MFA within them.
  • Implement automated password‑rotation and enforce strong, unique passwords for privileged accounts.
  • Deploy continuous log‑analysis for anomalous login patterns and retain evidence for SOC 2 audit trails.

Source: BleepingComputer

Technical Notes – The attack leveraged a public IPv6 range owned by LSHIY LLC, combined password‑spraying with reused credentials harvested from prior breaches, and abused the ROPC grant which bypasses interactive MFA. No post‑compromise activity was observed beyond credential validation. Source: same as above

📰 Original Source
https://www.bleepingcomputer.com/news/security/password-spraying-attacks-surge-155x-as-hackers-exploit-mfa-gaps/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →