Credential Stuffing
The latest Credential Stuffing coverage — news, analysis, and updates from the WindowsNews.AI desk.
Massive 24 Billion Credential Leak Sparks Urgent Windows and Microsoft 365 Security Response
An exposed Elasticsearch database containing more than 24 billion credentials—roughly 8.3 terabytes of usernames, email addresses, and passwords—was discovered by Cybernews researchers in...
Unsolicited Microsoft Verification Codes Signal Massive Credential-Stuffing Attack
A wave of unsolicited Microsoft verification codes is sweeping across Portugal and other regions in early 2026, triggering alarms among users who never attempted to sign in. Recipients report...
RDP Timing Attacks Explode to 30,000 Malicious IPs in Pre-Attack Reconnaissance on U.S. Schools
Last week, threat intelligence firm GreyNoise observed a coordinated scanning campaign targeting Microsoft Remote Desktop Protocol (RDP) services that rapidly escalated from an initial wave of nearly...
New Botnet Targets Microsoft 365 via Legacy Auth—Enable MFA Now
A sophisticated new botnet has emerged targeting Microsoft 365 users, employing advanced credential stuffing and password spraying techniques to breach enterprise accounts. Security researchers have...
Surging FastHTTP attacks exploit MFA fatigue to breach Microsoft 365 accounts
Microsoft 365 accounts are increasingly targeted by sophisticated FastHTTP cyber attacks, putting enterprise data at risk through credential stuffing and MFA fatigue tactics. These attacks leverage...
FastHTTP tool fuels 300% rise in Microsoft 365 brute-force attacks since Q2 2023.
Microsoft 365 users are facing a new wave of brute-force attacks leveraging the FastHTTP library to bypass security measures. Cybersecurity researchers have identified a sophisticated campaign where...