logo

Threat Brief: Mitigating Large-Scale Credential Attacks

ID: 2a85aa63-dbd9-52b4-b80c-92c795a3d8c2

STIX ID: report--2a85aa63-dbd9-52b4-b80c-92c795a3d8c2

Feed Name: Palo Alto Networks Unit 42

Threat Score
72/100

Date Published: 2026-06-20

Date Updated: 2026-06-20

Author: Andy Piazza

...
...

Unit 42 reports a large-scale credential spraying and credential-theft campaign targeting internet-exposed Fortinet, MSSQL, and Sophos services: actors use curated password lists for mass password spraying, exploit privilege escalation when possible to extract device configurations and stored credentials, crack credentials offline to expand their lists and establish persistent admin access, and an initial access broker claimed to be selling harvested credentials on Exploit.in; Unit 42 provides recommended hunting and hardening steps (MFA, zero trust, changing defaults, disabling unused accounts, patching) and offers incident response assistance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.