How the LSHIY Password-Spraying Attack Abuses OAuth’s ROPC Grant

What we learned from tracking a massive automated password spraying campaign on the Azure CLI that leveraged a depreciated OAuth flow.

cloudsecurity

Sources