Words published here do not necessarily reflect views of my employer or any other organization I am affiliated with. Research and analysis about malware, network forensics, and the intersection of crime with anything that electrons or photons flow through. Board member of World Cyber Health, the parent organization behind Malware Village and the NO-HAVOC project. Docent of obsolete technology at @mediaarchaeologylab Executive director, Elect More Hackers: electmorehackers.com "By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges." -- Cory Doctorow
Andrew 🌻 Brandt 🐇
@threatresearch@infosec.exchange
infosec.exchange
Microsoft 365 users and admins, beware! There's a specific IPv6 range (2a0a:d683::/32) operated by a provider called LSHIY that is engaging in password spraying / brute force login attempts against Microsoft accounts with old, previously leaked credentials that were disclosed as part of prior breaches.
The attack bypasses MFA and SSO because it uses deprecated but still functional OAuth Resource Owner Password Credentials 2.0 flow. But it works because some people still use creds that were stolen years ago and were never changed.
https://www.huntress.com/blog/lshiy-password-spray-attack
#M365 #bruteforce #passwordspray #compromise #weakpasswords
You've seen all posts