Microsoft Cautions Over Increase In Password Spraying Attacks

Share post:

According to Microsoft’s Detection and Response Team (DART), state-sponsored hackers, including the SolarWinds hackers, Nobelium and others, track identities with password spraying.

Password spraying is a variant of what is known as a brute force attack, in which the perpetrators attempt to gain unauthorized access to a single account by repeatedly guessing the password within a short period of time.

DART identified two main password spray techniques including the first known as “low and slow,” which simply means that a determined attacker uses a sophisticated password spray that uses “several individual IP addresses to attack multiple accounts at the same time with a limited number of curated guesses.”

The other method, “availability and reuse,” exploits previously compromised credentials that are published and sold on the dark web. According to Microsoft, “attackers can utilize this tactic, also called ‘credential stuffing’ to easily gain entry because it relies on people reusing passwords and username across sites.”

For more information, read the original story in ZDNet.

SUBSCRIBE NOW

Related articles

Cyber Security Today, May 15, 2024 – Ebury botnet still exploits Linux servers, Microsoft, SAP and Apple issue security updates

The Ebury botnet continues to exploit Linux servers, Microsoft, SAP and Apple issue security updates, and more. Welcome to...

Employee errors still predominant cause of data breaches: Verizon Report

In the latest 2024 Verizon Data Breach Report (DBIR), it has been revealed that employee errors remain the...

Black Basta has compromised over 500 organizations globally:CISA

The Cybersecurity and Infrastructure Security Agency (CISA) along with the FBI reported that the Black Basta ransomware group...

Cyber Security Today, May 10, 2024 – Patches for F5’s Next Central Manager released, Dell discovers data theft covering millions, and more

Patches for F5's Next Central Manager are released, Dell discovers data theft covering millions of buyers, and more Welcome...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways