← Back to feed
Threat Actors & CampaignsEmerging1 sourceJul 22, 2026 · 13:00via Huntress Blog

How the LSHIY Password-Spraying Attack Abuses OAuth’s ROPC Grant

Brief

What we learned from tracking a massive automated password spraying campaign on the Azure CLI that leveraged a depreciated OAuth flow.

Read more on Huntress Blog