home.social

#passwordspray — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #passwordspray, aggregated by home.social.

fetched live
  1. Microsoft 365 users and admins, beware! There's a specific IPv6 range (2a0a:d683::/32) operated by a provider called LSHIY that is engaging in password spraying / brute force login attempts against Microsoft accounts with old, previously leaked credentials that were disclosed as part of prior breaches.

    The attack bypasses MFA and SSO because it uses the deprecated (but still functional) OAuth Resource Owner Password Credentials 2.0 flow. But it works because some people still use creds that were stolen years ago and were never changed. So change your passwords, people!

    huntress.com/blog/lshiy-passwo

    #M365 #bruteforce #passwordspray #compromise #weakpasswords

  2. 📰 Iranian Hackers Launch Coordinated Password Spray Attacks on Middle East

    🇮🇷 Iranian APT Gray Sandstorm linked to password spray attacks against Israel & UAE. The campaign, targeting M365 accounts, appears coordinated with kinetic military strikes to aid in damage assessment. #APT #Iran #CyberWarfare #PasswordSpray

    🔗 cyber.netsecops.io/articles/ir

  3. Oh look, another thrilling tale of how #Microsoft bravely "uncovered" a password spray #attack with all the subtlety of a slow-motion car crash. 🚗💥 Apparently, logging in successfully is now a criminal offense—let's all panic! 😱🔍
    petrasecurity.substack.com/p/u #Security #PasswordSpray #CyberThreats #TechNews #PanicAlert #HackerNews #ngated

  4. Should a password spray detection in a SIEM alert you when there are 300+ failed logins against a collection of a dozen and a half accounts in an hour, or ONLY when one of those accounts subsequently logs in _successfully_ ?

    Is it only a password spray if it eventually succeeds?

    #detectionRules #passwordSpray

  5. 26 March 2024: "Cisco was made aware of multiple reports related to password spraying attacks aimed at RAVPN services. It has been noted by Talos that these attacks are not limited to Cisco products but also third-party VPN concentrators. Depending on your environment, the attacks can cause accounts to be locked, resulting in Denial of Service (DoS)-like conditions. This activity appears to be related to reconnaissance efforts." No CVE ID associated. Indicators of attack are provided. 🔗 cisco.com/c/en/us/support/docs

    See related Bleeping Computer reporting: bleepingcomputer.com/news/secu

    #Cisco #passwordspray #VPN #Fortinet #PaloAlto #SonicWall #botnet #Brutus