A massive, automated password spray attack has targeted Microsoft ’s Azure CLI , resulting in the compromise of at least 78 accounts through over 81 million login attempts . The attack, discovered by researchers at Huntress , exploited a specific OAuth flow that bypasses standard Multi-Factor Authentication (MFA) protections in misconfigured environments. The Azure CLI is emerging as one of the most dangerous security vulnerabilities in modern enterprise cloud infrastructures.

According to Huntress’ findings , the attack took place between June 12 and June 26, 2026 , and originated from an IPv6 address range (2a0a:d683::/32) controlled by internet infrastructure provider LSHIY LLC (AS32167) . The attackers used the OAuth ROPC (Resource Owner Password Credentials) flow — a method that was deprecated in OAuth 2.1 but is still supported in older configurations. This allowed them to bypass MFA in organizations that did not explicitly configure their policies to cover Azure CLI ROPC logins .
See also: Microsoft is being sued by shareholders over Azure slowdown and AI spending
The issue is rooted in a known loophole in Microsoft 's standard Conditional Access policies : historically, 11 of the company's first-party apps — including Azure CLI , Microsoft Teams , and Visual Studio — were exempt from these policies. This meant that even organizations that had enabled MFA globally remained vulnerable to attacks via Azure CLI , as the app was not subject to the authentication rules.
Azure CLI: How the password spray attack works
Azure CLI password spray works in a simple but effective way: attackers try a small number of passwords (often the most common) on a large number of accounts, thereby bypassing account lockout mechanisms. In this case, the OAuth ROPC flow allowed attackers to reuse validated credentials without requiring interaction with MFA , since the Conditional Access policy did not explicitly cover this authentication flow. The scale of the attack — 81 million attempts in just two weeks — highlights its automated nature and the significant resources at the attackers’ disposal.
Huntress points out that the conclusion is not that MFA is ineffective, but that organizations need to ensure that MFA policies cover all types of client applications and all authorization flows , with no exceptions. A “ Microsoft 365 MFA Bypass Toolkit ” (ConsentFix v3) was also recently discovered , which exploits exactly these exceptions in Conditional Access policies for first-party applications, allowing session reuse to bypass MFA. It’s worth noting that Microsoft ’s Conditional Access enforcement change on June 15, 2026 closed only one of the 11 known exceptions, leaving the rest — including the Azure CLI — still exposed.
See also: China: Microsoft cuts hundreds of Azure jobs

Azure CLI: Best practices for protection
Huntress researchers and other security experts recommend a number of measures to protect against Azure CLI password spray attacks . First, organizations should configure Conditional Access policies to require MFA for all users, all cloud applications, and all client application types without exceptions. Second, it is recommended to enable the `userStrongAuthClientAuthNRequired` setting in Conditional Access, which enforces strong client-level authentication and explicitly blocks ROPC flows .
Additionally, experts recommend restricting access to the Azure CLI to only administrators and developers who really need it, through specific user groups. Setting up service principals for high-risk applications and requiring user assignment before granting access significantly reduces the attack surface. For organizations not using advanced Conditional Access, enabling Security Defaults in Microsoft Entra ID blocks legacy authentication methods and device code flows, while requiring MFA for the Azure CLI. Finally, regularly monitoring sign-in logs for the Azure CLI and prioritizing alerts based on credential validity — and not just volume of attempts — is critical for early detection of real breaches.
See also: Microsoft reveals Storm-2949 attack on Azure Cloud and Microsoft 365

This attack is a wake-up call for any organization using Microsoft Azure. The fact that 78 accounts were compromised despite MFA proves that cloud security is not “set and forget” — it requires constant review and updating of policies. According to The Hacker News, Huntress continues to monitor the campaign and urges organizations to take immediate action to close the gaps in their authentication policies.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
