Iran targets M365 accounts with password-spraying attacks
2026-03-31T19:24:01Z•6c5eb00c0518468243621d8ee4a9355f2e95b0b1090d06b6a29ab18f596dddce
1k+LiteLLMPyPIRATTelnyxTrivyapi-keysaxioscitrix-netscalercloud-infectioncredential-stealerdata-breachdns-exfiltrationin-the-wild-exploitationiranm365npmopenaipassword-sprayingsupply-chain
What happened
A batch of high-impact security incidents and active campaigns was reported: multiple supply‑chain compromises (notably a hijacked npm maintainer that slipped a RAT into two axios releases and PyPI packages tied to the Trivy breach including LiteLLM and Telnyx) have led to credential‑stealing malware and over 1,000 cloud environments infected. In parallel, a critical Citrix NetScaler vulnerability is being exploited in the wild days after disclosure, OpenAI patched a ChatGPT DNS side‑channel data‑exfiltration flaw, and suspected Iran‑linked actors conducted large password‑spraying campaigns vs
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- 6c5eb00c0518468243621d8ee4a9355f2e95b0b1090d06b6a29ab18f596dddce
- Enrichment time
- 2026-03-31T19:24:01Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.