[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fSRHI7E_a4e5zBfOJmxB2hrhRc7a7TwaX3jmjGcw-aW0":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"6bdff0e1-b974-470e-8de7-a43b444bb563","iran-linked-password-spraying-campaign-exploits-weak-authentication-controls","f4ecb201-1058-4d00-a3bf-a5946a7eb4f6","Iran-Linked Password Spraying Campaign Exploits Weak Authentication Controls","Iranian threat actors successfully conducted large-scale password-spraying attacks against 300+ Israeli organizations by exploiting weak password policies and insufficient authentication controls in Microsoft 365 environments. The attackers used Tor networks and commercial VPNs to evade rate-limiting protections, demonstrating how inadequate monitoring and basic authentication mechanisms can be systematically bypassed. This campaign highlights the critical importance of multi-factor authentication and robust credential security, especially for organizations in geopolitically sensitive regions. The coordinated nature of these attacks across multiple countries shows how threat actors can scale credential-based attacks when proper access controls are not in place.","**Immediate actions:**\n- Enable multi-factor authentication (MFA) for all Microsoft 365 accounts, especially privileged users\n- Implement conditional access policies that block logins from suspicious IP ranges and Tor exit nodes\n- Review and strengthen password policies to prevent common and weak passwords\n\n**Long-term improvements:**\n- Deploy advanced threat protection solutions that can detect distributed password spraying patterns\n- Implement zero-trust architecture with continuous authentication validation\n- Establish geolocation-based access controls for sensitive accounts\n\n**Detection measures:**\n- Configure alerts for multiple failed login attempts across different accounts from similar IP ranges\n- Monitor for authentication attempts from VPN services and anonymization networks\n- Set up automated blocking of IP addresses showing suspicious authentication patterns",[12,13,14,15,16,17],"CIS Control 6 (Access Control Management)","CIS Control 8 (Audit Log Management)","NIST AC-2 (Account Management)","NIST AC-7 (Unsuccessful Logon Attempts)","NIST IA-2 (Identification and Authentication)","NIST SI-4 (Information System Monitoring)","published","2026-04-06T22:09:52.237148+00:00","2026-04-06T22:09:52.136+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F04\u002Firan-linked-password-spraying-campaign.html","iran-linked-password-spraying-campaign-targets-300-israeli-microsoft-365-organiz","Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":33,"name":34,"slug":35,"description":36,"color":37},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",[39],{"id":40,"date":41,"edition":42,"title":43,"audio_url":44},"cf2ceb1c-2710-47fb-97f6-739b32338646","2026-04-07","morning","ThreatNoir Morning Brief — April 7","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-04-07\u002Fthreatnoir-morning-brief-2026-04-07.mp3"]