logo

Conditional Access Misconfigurations Exposed 55 Orgs with MFA On

ID: ecdee599-f294-5bc3-832c-d2b8fc9603b6

STIX ID: report--ecdee599-f294-5bc3-832c-d2b8fc9603b6

Feed Name: Huntress Blog

Threat Score
78/100

Date Published: 2026-07-09

Date Updated: 2026-07-19

...
...

Huntress SOC observed two distinct, large-scale Microsoft 365 intrusion campaigns: a Railway-hosted device-code phishing operation (attributed to EvilTokens) that harvested long-lived OAuth tokens and affected 344 organizations, and an LSHIY-driven ROPC credential-replay surge (81 million attempts) that resulted in 78 account compromises across 64 organizations. Both attacks exploited allowed OAuth flows and narrowly-scoped Conditional Access policies that failed to block device code and ROPC authentication, demonstrating widespread configuration gaps that enable token theft and MFA bypass; Huntress recommends blocking device-code flow and tightening Conditional Access (all users, all cloud apps, legacy auth) and leveraging report-only learning modes to reduce breakage during deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.