Cybersecurity News

Filters
Tag
Reset

Filtered by tag: identity security × Clear

Device Code Phishing Keeps Evolving. Here’s What to Watch For

Attackers are abusing Microsoft 365's device code authentication flow to steal tokens without needing credentials. Victims are tricked into entering attacker-generated codes at legitimate Microsoft login pages, granting persistent access. The technique bypasses MFA and leaves minimal obvious indicators. Huntress advises monitoring for unusual device code authentication requests, unexpected token grants, and sign-ins from unfamiliar locations or clients.

How the LSHIY Password-Spraying Attack Abuses OAuth’s ROPC Grant

Researchers tracked a large automated password-spraying campaign targeting Azure CLI that exploited OAuth's Resource Owner Password Credentials grant, a deprecated flow still supported by many systems. Attackers used it to avoid modern authentication defenses like MFA prompts and conditional access policies. The campaign, dubbed LSHIY, highlights risks of legacy OAuth flows remaining enabled, and researchers recommend disabling ROPC grants where possible.

Conditional Access Misconfigurations Exposed 55 Orgs with MFA On

Huntress researchers found that Conditional Access misconfigurations left 55 organizations vulnerable despite having MFA enabled. Two real attack cases bypassed policies that appeared properly set up, exposing gaps invisible to standard reviews. Huntress's Managed Identity Security Posture Management tool is designed to detect these configuration flaws before attackers can exploit them.