Get the latest tech news
Massive botnet hits Microsoft 365 accounts
A botnet of over 130,000 compromised devices is launching coordinated password-spraying attacks against Microsoft 365 accounts.
Security researchers at SecurityScorecard are examining possible connections to China-affiliated threat actors, citing evidence of infrastructure linked to CDS Global Cloud and UCLOUD HK, which have operational ties to China. Unlike previous attacks linked to Volt Typhoon(China) and APT33 (Iran), this botnet leverages Non-Interactive Sign-Ins to avoid detection by traditional security controls. Growing trend: Similar tactics have been observed in past campaigns, particularly targeting government agencies, critical infrastructure, and large enterprises.
Or read this on r/technology