Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs
2026-07-01T14:51:48Z•9a62615a907a301806d695c2addb47150f34e3e34ad1f68b63e0a230e202a95c
aflac-japanappleazure-clibluehammercve-2026-33825cve-2026-46817cve-2026-48558data-breachguardfalliot-botnetknown-exploited-vulnerabilitiesoracle-e-businesspassword-sprayprivilege-escalationransomwarerustduckshell-injectionsimplehelpthreat-actor-activitywebkit-patches
What happened
Feed highlights multiple high-impact incidents and vulnerabilities: a massive LSHIY password-spray campaign targeting Azure CLI (~81M login attempts, multiple org compromises); CISA confirms BlueHammer (CVE-2026-33825) is being used in ransomware to gain SYSTEM privileges via Microsoft Defender; SimpleHelp auth-bypass (CVE-2026-48558, CVSS 10.0) added to CISA’s Known Exploited Vulnerabilities catalog; a critical Oracle E-Business Suite flaw (CVE-2026-46817, CVSS 9.8) is being actively exploited; emergence of the RustDuck IoT DDoS botnet; GuardFall — a universal shell-injection issue affecting
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 9a62615a907a301806d695c2addb47150f34e3e34ad1f68b63e0a230e202a95c
- Enrichment time
- 2026-07-01T14:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.