Railway. LSHIY. Different Auth Flows, but the Same Lesson We Keep Skipping
Two Microsoft 365 attacks got through Conditional Access policies that seemed fully configured. Learn what went wrong and how Huntress Managed ISPM catches these gaps first.
Two Microsoft 365 attacks got through Conditional Access policies that seemed fully configured. Learn what went wrong and how Huntress Managed ISPM catches these gaps first.
Huntress is seeing an ongoing password spray attack against Microsoft Azure CLI that originates from an IPv6 address range controlled by LSHIY LLC.
Attackers turned Railway.com's free cloud platform into a Microsoft 365 token-stealing machine, hitting 268+ organizations and 100+ MSPs. Here's the full infrastructure breakdown.