Conditional Access Misconfigurations Exposed 55 Orgs with MFA On
ID: ecdee599-f294-5bc3-832c-d2b8fc9603b6
STIX ID: report--ecdee599-f294-5bc3-832c-d2b8fc9603b6
Feed Name: Huntress Blog
Huntress SOC observed two distinct, large-scale Microsoft 365 intrusion campaigns: a Railway-hosted device-code phishing operation (attributed to EvilTokens) that harvested long-lived OAuth tokens and affected 344 organizations, and an LSHIY-driven ROPC credential-replay surge (81 million attempts) that resulted in 78 account compromises across 64 organizations. Both attacks exploited allowed OAuth flows and narrowly-scoped Conditional Access policies that failed to block device code and ROPC authentication, demonstrating widespread configuration gaps that enable token theft and MFA bypass; Huntress recommends blocking device-code flow and tightening Conditional Access (all users, all cloud apps, legacy auth) and leveraging report-only learning modes to reduce breakage during deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
