Password Spraying Attacks Rise As Attackers Target Microsoft Azure MFA Gaps
Huntress has reported a 155x increase in password spraying attacks during 2026, with attackers exploiting Azure CLI access and gaps in MFA protection.
Huntress has reported a 155x increase in password spraying attacks during 2026, with attackers exploiting Azure CLI access and gaps in MFA protection.
TrendAI intelligence supports an international investigation into Tycoon 2FA, with NCCIA, INTERPOL and Singapore Police Force leading coordinated action.
German, US, and Indonesian authorities dismantled the Kratos phishing infrastructure used to steal Microsoft 365 sessions, bypass MFA, and target victims across more than 30 countries.
Huntress has identified a large scale password spray campaign targeting Azure CLI, with more than 81 million login attempts compromising at least 78 Microsoft accounts across 64 organizations.
A government advisory based on Cisco Talos report links most 2024 cyberattacks in Pakistan to weak security practices, lack of MFA, and insecure tools.
Pakistan’s National Computer Emergency Team issues urgent advisory on CVE-2025-20286, a critical vulnerability in Cisco ISE cloud deployments that allows full access without a password.