CuraSec

tag: Password-Spraying · 1 items

2026-08-20 · BleepingComputer · source ↗ #identity-security#mfa#password-spraying
  • Engineer — Plan: Audit all login flows for legacy authentication exposure and enforce MFA uniformly — the campaign scale (81M attempts in two weeks) confirms attackers are systematically targeting incomplete MFA coverage and legacy auth protocols. Disable legacy auth (SMTP AUTH, Basic auth, IMAP) in M365/Google Workspace and review Conditional Access or equivalent policies this quarter.
  • SOC/IR — Act: Tune SIEM for distributed low-and-slow authentication failures, particularly against legacy protocol endpoints (SMTP, IMAP, RDP, ADFS); run a hunt for accounts with high failed-login volume or successful logins following a spray pattern since the start of H1 2026. Password spraying maps to ATT&CK T1110.003 and is detectable via authentication log anomalies even without specific IOCs.
  • Leader — Plan: The 155x year-over-year increase from Huntress provides a quantified data point to accelerate legacy auth deprecation and full MFA rollout on the roadmap; use it to justify priority and budget before the next planning cycle, framing the gap in MFA coverage as a measurable risk rather than a configuration detail.