Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts
A vast, continuing automated password spray attack targeting Microsoft's Azure command-line interface (CLI) has compromised dozens of accounts, according to cybersecurity analysts.
According to Huntress, internet infrastructure provider LSHIY LLC (AS32167) controls the IPv6 address range (2a0a:d683::/32) from where the activity originated.
The threat actor responsible made over 81 million login attempts between June 12 and June 26, effectively compromising at least 78 Microsoft accounts across 64 businesses, according to a statement from the firm. These attacks don't seem to target any particular business type or industry; instead, they seem to be focused solely on the frequency of passwords in compromised password combo lists.
The size of the password spray attack is notable, as...

