[SITUATION] · [QUIET]
3 clusters · 8 sources · 22 days · First seen · Last updated
Categories: TECHNOLOGY
Microsoft 365 and cloud MFA‑bypass trends
Overview
In mid‑June, ESET’s analysis of the 2026 Verizon breach report showed software‑vulnerability exploits overtaking credential theft as the most common breach trigger, with AI tools speeding discovery and exploitation. The same briefing highlighted a phishing campaign that used fake Microsoft 365 login pop‑ups to steal credentials.
A few weeks later, investigators documented a massive password‑spray operation targeting Microsoft 365 and Azure CLI accounts. The attackers leveraged leaked credentials and the deprecated OAuth Resource Owner Password Credentials flow to bypass MFA, compromising 78 accounts across 64 organisations. The campaign underscored continued risks from mis‑configured conditional‑access policies and legacy authentication methods.
Further investigation identified the attack traffic originating from an IPv6 range (2a0a:d683::/32) registered to LSHIY LLC, a provider with offices in Hong Kong, Wuhan and New York, indicating Chinese‑linked infrastructure. Recommendations emphasized disabling the legacy ROPC flow, enforcing MFA for all cloud apps, and tightening Conditional Access rules.
Separately, researchers reported an APT‑style campaign (Umbrij) that harvests OAuth tokens from active Chrome or Edge sessions via a ShadowToken toolkit and remote‑debug techniques. By hijacking browser‑based tokens, the group compromised Gmail accounts without stealing passwords or triggering 2FA, illustrating a new MFA‑bypass vector beyond password‑spray.
Together, these developments show attackers exploiting both outdated authentication flows in Microsoft 365/Azure and emerging token‑hijacking techniques to evade MFA, highlighting the need for comprehensive token‑security controls and the deprecation of legacy protocols.
Timeline
-
about 1 month ago
[TECHNOLOGY] 3 sourcesCloud hacks bypass MFA via token hijacking and password‑sprayAPT group Umbrij hijacks Gmail OAuth tokens to bypass 2FA, while a password‑spray attack on Azure CLI compromised 78 Microsoft accounts using a deprecated ROPC flow, exposing MFA gaps.
-
about 1 month ago
[TECHNOLOGY] 3 sourcesMicrosoft 365 password‑spray campaign compromises 78 accounts across 64 organizationsA password‑spray wave made 81 million login attempts on Microsoft 365/Azure CLI between June 12‑26 2026, breaching 78 accounts in 64 firms by exploiting ROPC and weak Conditional Access settings.
-
about 2 months ago
[TECHNOLOGY] 2 sourcesSoftware Vulnerabilities Overtake Credential Theft as Leading Cyber‑Attack VectorSoftware flaws now lead cyber attacks, with slow patching leaving companies exposed; a new phishing scheme uses fake Microsoft 365 login pop‑ups, prompting direct‑login and 2FA safeguards.
Sources
blogspan.net · cybersecuritynews.com · elpueblodigital.uy · it-boltwise.de · it-daily.net · itnerd.blog · redeszone.net · zehn.de