Skip to content
Threat Feed

Tag

Password-Spraying

13 briefs RSS
medium advisory

Threat Actors Use Claude AI to Target Water Utility OT Assets

An unidentified threat actor used Claude AI to identify and target a vNode SCADA/IIoT management interface at a Mexican water utility between December 2025 and February 2026, ultimately failing to gain access.

AI OT SCADA password-spraying reconnaissance
2r 2t
low advisory

Spike in Successful Logon Events from a Source IP

A machine learning job detected a spike in successful authentication events from a source IP address, which can indicate password spraying, user enumeration, or brute force activity, potentially leading to credential access.

credential-access defense-evasion brute-force password-spraying
2r 3t
high advisory

AWS Password Spraying Attack via Multiple Failed Console Logins

A single source IP attempts to authenticate to the AWS Console against multiple unique user accounts within a short timeframe, indicating a potential password spraying attack.

AWS Console aws password-spraying credential-access
2r 2t
medium advisory

Okta Password Spray Attempt Detection

Detection of Okta password spraying attempts by identifying multiple failed login attempts from different source IPs targeting the same user account.

Okta credential-access password-spraying
2r 1t
high advisory

Azure AD Password Spraying Attack Detection

A single source IP failing to authenticate with multiple valid users in Azure AD, potentially indicating a Password Spraying attack, is detected using Azure SignInLogs and the 3-sigma rule to identify anomalous failed login patterns.

Azure Active Directory azuread password-spraying cloud
2r 3t
high advisory

Password Spray Attack Detection via 3-Sigma Anomaly

This analytic detects password spraying attacks by identifying an unusual volume of failed authentication attempts from a single source using a 3-sigma deviation from the average, leveraging the Authentication Data Model for broad CIM-mapped event coverage.

Windows password-spraying credential-access
2r 1t
high advisory

Okta ThreatInsight Detection of Credential Access Attempts

Okta ThreatInsight detected events indicating password spraying, login failures, and high counts of unknown user login attempts, potentially leading to unauthorized access and credential compromise.

Okta Identity Cloud okta credential-access password-spraying account-takeover
2r 1t
high advisory

Okta Multiple Users Failing Authentication From Single IP

Multiple users failing to authenticate from a single IP address within a short timeframe in Okta indicates potential brute-force or password spraying attacks, leading to unauthorized access and data breaches.

Okta brute-force password-spraying credential-access
2r 1t
high advisory

Okta Multiple Account Lockouts Indicative of Password Spraying

Multiple Okta accounts locked out within a 5-minute period, detected via aggregated user.account.lock events, may indicate a password spraying attack leading to potential account takeovers.

Okta password-spraying account-lockout
2r 1t
high advisory

High Number of Failed Office 365 Logins from Single Source

The analytic detects multiple failed login attempts in Office365 Azure Active Directory from a single source IP address, potentially indicating brute-force or password spraying attacks.

Office 365 +1 cloud office365 credential-access password-spraying
1r 1t
high advisory

AWS High Number of Failed Console Login Attempts

An IP address exhibiting more than 20 failed AWS console login attempts within a 5-minute window, indicative of potential brute-force or password spraying attacks against AWS accounts.

AWS cloudtrail brute-force password-spraying credential-access
2r 2t
high advisory

AWS Console Login Password Spraying

A single source IP failing to authenticate into the AWS Console with multiple valid users, potentially indicating a password spraying attack against cloud resources.

AWS Console aws cloudtrail password-spraying
2r 3t
high advisory

GCP Password Spraying Detection

A single source IP is failing to authenticate into Google Workspace with multiple valid users, potentially indicating a Password Spraying attack.

Google Workspace gcp password-spraying cloud
2r 2t