Password spraying attacks surge 155x, exploiting legacy authentication flaws
VulnThe campaign, originating from an IPv6 range provided by LSHIY LLC, leveraged reused credentials and the legacy Resource Owner Password Credentials (ROPC) OAuth grant, which bypasses multi-factor authentication (MFA) and single sign-on (SSO).
Read full story at SC Media →