Botnet targets Basic Auth in Microsoft 365 password spray attacks
Password-spray assaults against Microsoft 365 (M365) accounts globally are being carried out by a vast botnet of more than 130,000 infected machines, which targets basic authentication in order to circumvent multi-factor authentication.
According to a SecurityScorecard assessment, the attackers are targeting the accounts on a broad scale by using credentials that were acquired by infostealer malware.
To get beyond Multi-Factor Authentication (MFA) safeguards and obtain unauthorized access without setting off security alerts, the assaults rely on non-interactive sign-ins using Basic Authentication (Basic Auth).
Businesses that only use interactive sign-in monitoring are unaware of these threats read more about Botnet targets Basic Auth in Microsoft 365 password spray attacks.
G...

