[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1-H1gvkB61T1Ih8utrY1BHFmBsqqIxicFbQyncGga14":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"2070da5f-da43-4de9-9c17-8617a21010b7","password-spraying-surge-exploits-mfa-gaps-and-legacy-auth","e748ed47-98d0-40a2-9942-29b64d6b1f05","Password Spraying Surge Exploits MFA Gaps and Legacy Auth","Attackers launched a massive password spraying campaign — 155 times larger than baseline levels — by targeting legacy authentication protocols like OAuth Resource Owner Password Credentials (ROPC) that bypass modern MFA controls. Organizations that have not disabled legacy authentication endpoints or enforced consistent MFA policies across all access paths remain dangerously exposed. The use of IPv6 address ranges from an obscure provider further evaded traditional IP-based blocklists and detection tools, highlighting how attackers actively route around defensive controls. This matters because a single unprotected authentication pathway can render an entire MFA deployment ineffective, allowing mass credential compromise at scale.","**Immediate Actions:**\n- Disable legacy authentication protocols (OAuth ROPC, Basic Auth, SMTP AUTH) across all Microsoft 365 and Azure tenants immediately.\n- Audit and enforce MFA on ALL authentication paths, including Azure CLI, service principals, and API endpoints — not just interactive logins.\n- Block or throttle authentication attempts from anonymizing infrastructure and unfamiliar IPv6 ranges at the perimeter.\n\n**Long-Term Improvements:**\n- Implement Conditional Access policies that explicitly deny legacy authentication flows and require compliant devices for sensitive resources.\n- Adopt a Zero Trust architecture ensuring no authentication method can bypass MFA regardless of protocol or client type.\n- Regularly review OAuth application permissions and remove or restrict any app registrations that use password-based credential flows.\n\n**Detection Measures:**\n- Configure SIEM alerting for abnormal authentication volume spikes, failed login bursts, or sudden IPv6-sourced login attempts.\n- Enable Microsoft Entra ID (Azure AD) sign-in logs and set alerts for legacy authentication protocol usage.\n- Establish baseline login behavior per user and trigger automated account lockout or step-up authentication when anomalies are detected.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 4.1 – Establish and Maintain a Secure Configuration Process","CIS Control 6.3 – Require MFA for Externally-Exposed Applications","CIS Control 6.4 – Require MFA for Remote Network Access","CIS Control 8.2 – Collect Audit Logs","NIST SP 800-53 AC-2 – Account Management","NIST SP 800-53 AC-17 – Remote Access","NIST SP 800-53 IA-5 – Authenticator Management","NIST SP 800-53 SI-4 – System Monitoring","NIST SP 800-63B – Digital Identity Guidelines (AAL2\u002FAAL3 MFA requirements)","Microsoft Secure Score – Block Legacy Authentication Recommendation","ITIL – Event Management \u002F Incident Detection","GDPR Article 32 – Security of Processing (technical measures to ensure confidentiality)","published","2026-08-19T16:21:10.417054+00:00","2026-08-19T16:21:10.105+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fpassword-spraying-attacks-surge-155x-as-hackers-exploit-mfa-gaps\u002F","password-spraying-attacks-surge-155x-as-hackers-exploit-mfa-gaps-3480c4","Password spraying attacks surge 155x as hackers exploit MFA gaps",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":39,"name":40,"slug":41,"description":42,"color":43},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":45,"name":46,"slug":47,"description":48,"color":49},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]