As cited
Copy frozen at (site build).
threat intel
No (Bad) CAP: Inside an Ongoing LSHIY Password Spray Attack
Huntress researchers have identified an ongoing password spray campaign targeting Microsoft Azure CLI that originates from an IPv6 address range operated by LSHIY LLC. The attackers are attempting to compromise Azure accounts through brute force authentication attempts.
Why it matters: Organizations using Azure CLI are at risk of unauthorized account access if weak or default credentials are in use; practitioners should review access logs, enforce conditional access policies, and ensure strong password practices.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
No (Bad) CAP: Inside an Ongoing LSHIY Password Spray Attack
Huntress researchers have identified an ongoing password spray campaign targeting Microsoft Azure CLI that originates from an IPv6 address range operated by LSHIY LLC. The attackers are attempting to compromise Azure accounts through brute force authentication attempts.
Why it matters: Organizations using Azure CLI are at risk of unauthorized account access if weak or default credentials are in use; practitioners should review access logs, enforce conditional access policies, and ensure strong password practices.
- Source published
- First seen by Cybersecurity Tracker