Microsoft 365 Hit by 81 Million Login Attempts [Prime Cyber Insights]
Welcome to Prime Cyber Insights. This is your briefing on high-stakes digital risk. <br/><i>acting_description:</i> professional, steady, leading <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 Today, we are dissecting a massive credential offensive against Microsoft 365 and the automation of session hijacking. <br/><i>acting_description:</i> engaged, measured, clear <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.4 We begin with a high-volume campaign reported this week. Between June 12th and 26th, over 81 million login attempts targeted Microsoft 365 accounts. This was not a standard brute-force spray, but a targeted exploitation of the Resource Owner Password Credentials, or R-O-P-C, OAuth flow. <br/><i>acting_description:</i> analytical, direct, factual <i>speed:</i> 0.98 <i>trailing_silence:</i> 0.3 What is striking, Aaron, is how attackers used the Azure CLI to bypass authentication. Huntress observed that many compromised organizations had MFA implemented via Conditional Access Policies, but those policies were not configured to cover this specific R-O-P-C flow. The password goes directly to the token endpoint without an interactive MFA prompt. <br/><i>acting_description:</i> responsive, observant, thoughtful <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 In several cases, MFA was only enforced for administrators or traffic from untrusted locations. Attackers only needed a single matching credential set to gain entry. It is also worth noting that some breached firms had MFA in report-only mode, so it was never actually applied. Lauren, this connects to the rise of Phishing-as-a-Service platforms we are tracking. <br/><i>acting_description:</i> technical, objective, firm <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.4 Exactly. Researchers at Cisco Talos recently identified ARToken, a management panel operating as an affiliate of the EvilTokens platform. It exposes more than 80 API endpoints and uses AI to ingest harvested mailboxes and draft BEC campaigns. It is a commercial toolkit available for approximately 1,500 dollars. <br/><i>acting_description:</i> informed, precise, collaborative <i>speed:</i> 0.98 <i>trailing_silence:</i> 0.3 The sophistication is now evolving into ConsentFix attacks. Reports indicate attackers are using drag-and-drop links to hijack OAuth tokens. an agent believes they are completing a login, drags a link into their browser, and the session is hijacked in seconds. No credentials required, just session theft. <br/><i>acting_description:</i> serious, methodical, authoritative <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 It turns routine user habits into vulnerabilities. This shift toward session hijacking is why identity monitoring is becoming as vital as the initial authentication. On the subject of identity, Apple is facing scrutiny for a year-old unfixed flaw in its Hide My Email feature. Although reported in June 2025, findings confirm it can still expose an agent's primary email address. <br/><i>acting_description:</i> insightful, calm, cautionary <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.4 That is a significant delay for a privacy fix. Meanwhile, Medtronic has begun notifying customers impacted by a ShinyHunters intrusion from April. The breach involves nine million records, including Social Security numbers and health data. While Medtronic states medical devices remain safe, the exposure of personally identifiable information is substantial. <br/><i>acting_description:</i> critical, poised, steady <i>speed:</i> 0.98 <i>trailing_silence:</i> 0.3 The pattern here, Aaron, is clear. Automation is shortening the distance between a minor misconfiguration and a full-scale compromise. Whether it is an R-O-P-C flow or a ShinyHunters extortion attempt, the speed of response dictates the fallout. <br/><i>acting_description:</i> analytical, rhythmic, perceptive <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 For practitioners, the takeaway is clear: restrict Azure CLI access to administrators and ensure MFA covers all cloud applications and client types, not just web logins. <br/><i>acting_description:</i> pragmatic, instructive, direct <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.4 This has been Prime Cyber Insights. For full technical details, visit pci.neuralnewscast.com. This program is for educational purposes only. Neural Newscast is AI-assisted, human reviewed. View our AI Transparency Policy at NeuralNewscast.com. <br/><i>acting_description:</i> composed, professional, conclusive <i>speed:</i> 0.95 <i>trailing_silence:</i> 0.5

