CYBERSECURITYTRACKER
TRACKING
Permanent story citation

How the LSHIY Password-Spraying Attack Abuses OAuth’s ROPC Grant

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4661

As cited

Copy frozen at (site build).

threat intel

How the LSHIY Password-Spraying Attack Abuses OAuth’s ROPC Grant

A large-scale automated password-spraying campaign targeted Azure CLI by exploiting the Resource Owner Password Credentials (ROPC) OAuth grant type, which is deprecated in modern OAuth implementations. Researchers identified and tracked the campaign to understand how attackers leveraged this legacy flow to conduct brute-force authentication attacks at scale.

Why it matters: Organizations using Azure CLI and legacy OAuth flows face active brute-force threats; practitioners should review authentication policies, disable deprecated OAuth grant types, and implement rate limiting on failed login attempts.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

How the LSHIY Password-Spraying Attack Abuses OAuth’s ROPC Grant

A large-scale automated password-spraying campaign targeted Azure CLI by exploiting the Resource Owner Password Credentials (ROPC) OAuth grant type, which is deprecated in modern OAuth implementations. Researchers identified and tracked the campaign to understand how attackers leveraged this legacy flow to conduct brute-force authentication attacks at scale.

Why it matters: Organizations using Azure CLI and legacy OAuth flows face active brute-force threats; practitioners should review authentication policies, disable deprecated OAuth grant types, and implement rate limiting on failed login attempts.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary