Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs

2026-07-01T14:51:48Z9a62615a907a301806d695c2addb47150f34e3e34ad1f68b63e0a230e202a95c
aflac-japanappleazure-clibluehammercve-2026-33825cve-2026-46817cve-2026-48558data-breachguardfalliot-botnetknown-exploited-vulnerabilitiesoracle-e-businesspassword-sprayprivilege-escalationransomwarerustduckshell-injectionsimplehelpthreat-actor-activitywebkit-patches

What happened

Feed highlights multiple high-impact incidents and vulnerabilities: a massive LSHIY password-spray campaign targeting Azure CLI (~81M login attempts, multiple org compromises); CISA confirms BlueHammer (CVE-2026-33825) is being used in ransomware to gain SYSTEM privileges via Microsoft Defender; SimpleHelp auth-bypass (CVE-2026-48558, CVSS 10.0) added to CISA’s Known Exploited Vulnerabilities catalog; a critical Oracle E-Business Suite flaw (CVE-2026-46817, CVSS 9.8) is being actively exploited; emergence of the RustDuck IoT DDoS botnet; GuardFall — a universal shell-injection issue affecting

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
9a62615a907a301806d695c2addb47150f34e3e34ad1f68b63e0a230e202a95c
Enrichment time
2026-07-01T14:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs · Baitaphish