Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
Humana To Divest End-Of-Life Care Business For 0 Million

Humana To Divest End-Of-Life Care Business For $900 Million

11 June 2026
Anthropic accused of ‘secret sabotage’ as Claude Fable 5 silently limits AI research capabilities

Anthropic accused of ‘secret sabotage’ as Claude Fable 5 silently limits AI research capabilities

11 June 2026
NYT ‘Pips’ Hints, Answers And Walkthrough For Thursday, June 11

NYT ‘Pips’ Hints, Answers And Walkthrough For Thursday, June 11

11 June 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » Microsoft Confirms Password Spraying Attack — What You Need To Know
Innovation

Microsoft Confirms Password Spraying Attack — What You Need To Know

Press RoomBy Press Room28 April 20253 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
Microsoft Confirms Password Spraying Attack — What You Need To Know

With a billion stolen passwords up for sale on dark web criminal marketplaces, and infostealer malware attacks continuing to add to that number, it’s no wonder that cybercriminals are turning to automatic password hacking machines in their nefarious campaigns. I have previously reported on password spray and pray attacks against Windows users without two-factor authentication, now Microsoft has issued a warning of a new password spraying attack by a hacking group identified only as Storm-1977 that is targeting cloud tenants.

Beware This Password Spraying Attack, Microsoft Warns

The Microsoft Threat Intelligence team has published a new warning after observing hackers taking particular advantage of unsecured workload identities in order to gain access to containerized environments. With Microsoft research showing that 51% of such workload identities being completely inactive over the past year, it’s no wonder that threat actors are exploiting this attack surface. “As the adoption of containers-as-a-service among organizations rises,” the report said, “Microsoft Threat Intelligence continues to monitor the unique security threats that affect containerized environments.” One of these is the password spraying attack, specifically targeting cloud tenants in the education sector, that has now been pinned on the Storm-1977 threat group.

The password spraying attack exploited a command line interface tool called AzureChecker to “download AES-encrypted data that when decrypted reveals the list of password spray targets,” the report said. It then, to add salt to the now open wound, accepted an accounts.txt file containing username and password combinations used for the attack, as input. “The threat actor then used the information from both files and posted the credentials to the target tenants for validation,” Microsoft explained.

The successful attack enabled the Storm-1977 hackers to then leverage a guest account in order to create a compromised subscription resource group and, ultimately, more than 200 containers that were used for cryptomining.

Mitigating The Password Spraying Container Attack Threat

Microsoft said that, in light of attackers such as Storm-1977
increasingly using compromised identities for initial access as well as long-term persistence within an environment, the following mitigations are recommended:

  • Use strong authentication when exposing sensitive interfaces to the internet.
  • Use strong authentication methods for the Kubernetes API to help prevent attackers from gaining access to the cluster even if valid credentials such as kubeconfig are obtained.
  • Avoid using the read-only endpoint of Kubelet on port 10255, which doesn’t require authentication.
  • Configure the Kubernetes role-based access controls for each user and service account to have only those permissions that are absolutely necessary.

I have reached out to Microsoft for further information regarding the Storm-1977 password spraying attack campaign.

Azure AzureChecker Education enterprise Hackers Kubernetes Microsoft Password Attack Password Spraying Storm-1977
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

Humana To Divest End-Of-Life Care Business For 0 Million

Humana To Divest End-Of-Life Care Business For $900 Million

11 June 2026
NYT ‘Pips’ Hints, Answers And Walkthrough For Thursday, June 11

NYT ‘Pips’ Hints, Answers And Walkthrough For Thursday, June 11

11 June 2026
Gates testifies on Epstein: Fortune reported payments to his ex-girlfriend, M Microsoft deal

Gates testifies on Epstein: Fortune reported payments to his ex-girlfriend, $1M Microsoft deal

11 June 2026
Today’s Wordle #1818 Hints And Answer For Thursday, June 11

Today’s Wordle #1818 Hints And Answer For Thursday, June 11

10 June 2026
Millions Of Samsung Galaxy Phones Are In Line For A Free Upgrade

Millions Of Samsung Galaxy Phones Are In Line For A Free Upgrade

10 June 2026
Apple iOS 27 Release Creates A Price Problem For iPhone 15 Owners

Apple iOS 27 Release Creates A Price Problem For iPhone 15 Owners

10 June 2026
Don't Miss
Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

By Press Room27 December 2024

Every year, millions of people unwrap Christmas gifts that they do not love, need, or…

Exclusive: DeFi platform Azura launches after raising .9 million from Initialized

Exclusive: DeFi platform Azura launches after raising $6.9 million from Initialized

22 October 2024
Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

22 October 2024
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
Today’s Wordle #1818 Hints And Answer For Thursday, June 11

Today’s Wordle #1818 Hints And Answer For Thursday, June 11

10 June 20262 Views
The curse of Trump watching sports in person: the home team seems to always lose

The curse of Trump watching sports in person: the home team seems to always lose

10 June 20262 Views
Millions Of Samsung Galaxy Phones Are In Line For A Free Upgrade

Millions Of Samsung Galaxy Phones Are In Line For A Free Upgrade

10 June 20261 Views
Digital sovereignty isn’t the same thing as digital isolation. Asia’s governments should be careful

Digital sovereignty isn’t the same thing as digital isolation. Asia’s governments should be careful

10 June 20262 Views

Recent Posts

  • Humana To Divest End-Of-Life Care Business For $900 Million
  • Anthropic accused of ‘secret sabotage’ as Claude Fable 5 silently limits AI research capabilities
  • NYT ‘Pips’ Hints, Answers And Walkthrough For Thursday, June 11
  • Gates testifies on Epstein: Fortune reported payments to his ex-girlfriend, $1M Microsoft deal
  • Today’s Wordle #1818 Hints And Answer For Thursday, June 11

Recent Comments

No comments to show.
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
Humana To Divest End-Of-Life Care Business For 0 Million

Humana To Divest End-Of-Life Care Business For $900 Million

11 June 2026
Anthropic accused of ‘secret sabotage’ as Claude Fable 5 silently limits AI research capabilities

Anthropic accused of ‘secret sabotage’ as Claude Fable 5 silently limits AI research capabilities

11 June 2026
NYT ‘Pips’ Hints, Answers And Walkthrough For Thursday, June 11

NYT ‘Pips’ Hints, Answers And Walkthrough For Thursday, June 11

11 June 2026
Most Popular
Gates testifies on Epstein: Fortune reported payments to his ex-girlfriend, M Microsoft deal

Gates testifies on Epstein: Fortune reported payments to his ex-girlfriend, $1M Microsoft deal

11 June 20261 Views
Today’s Wordle #1818 Hints And Answer For Thursday, June 11

Today’s Wordle #1818 Hints And Answer For Thursday, June 11

10 June 20262 Views
The curse of Trump watching sports in person: the home team seems to always lose

The curse of Trump watching sports in person: the home team seems to always lose

10 June 20262 Views

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • March 2022
  • January 2021
  • March 2020
  • January 2020

Categories

  • Blog
  • Business
  • Entrepreneurs
  • Global
  • Innovation
  • Leadership
  • Living
  • Money & Finance
  • News
  • Press Release
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.