Hackers target Microsoft 365 accounts with 81 million login attempts
A massive password-spraying campaign has been targeting Microsoft 365 accounts, generating over 81 million login attempts over a two-week period. The threat actor used valid username and password combinations exposed in past breaches to attempt authentication via Microsoft’s Azure command-line interface (CLI). Once authenticated, the hacker exploited a vulnerability in Conditional Access policies, bypassing multi-factor … Read more