CuraSec

tag: Credential-Spraying · 1 items

  • Engineer — Plan: TeamFiltration targets M365 tenants using default/weak credentials; audit your tenant for accounts lacking MFA and enforce Conditional Access policies requiring phishing-resistant auth before this campaign broadens its target geography.
  • SOC/IR — Act: Active M365 credential-spray campaign is live and compromising accounts; hunt for TeamFiltration enumeration patterns in Azure AD sign-in logs and flag clusters of authentication attempts originating from AWS EC2 CIDR ranges with mixed failure/success ratios.
  • Leader — Learn: Seven-account compromise across 28 tenants is low scale and currently regional (Chilean retail/finance), but the default-password attack path is a useful data point for board-level conversations about basic credential hygiene and MFA adoption metrics.