Microsoft 365 users and admins, beware! There's a specific IPv6 range (2a0a:d683::/32) operated by a provider called LSHIY that is engaging in password spraying / brute force login attempts against Microsoft accounts with old, previously leaked credentials that were disclosed as part of prior breaches. The attack bypasses MFA and SSO because it uses deprecated but still functional OAuth Resource Owner Password Credentials 2.0 flow. But it works because some people still use creds that were stolen years ago and were never changed. https://www.huntress.com/blog/lshiy-password-spray-attack #M365 #bruteforce #passwordspray #compromise #weakpasswords