Fifteen of the twenty-three had MFA — and it did not apply to the door the attacker used
2026-08-20Security
Huntress reports password spraying up 155x in the first half of 2026, driven by a campaign against Azure CLI that abuses ROPC, a deprecated OAuth grant which posts your username and password straight to the token endpoint with no interactive MFA prompt. In two weeks it made 81 million login attempts.