threat-intel Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts A massive, automated password spray attack targeting Microsoft's Azure CLI compromised at least 78 Microsoft accounts across 64 organizations. The attack leveraged a deprecated OAuth flow (ROPC) to bypass Conditional Access Policy (CAP) protections, exploiting prevalent password combinations from compromised lists. Thi… The Hacker News · Jul 1, 2026 High USCNpassword sprayropcconditional access