Here’s the irony of the week: a wallet-draining phishing kit, a chatbot that generated graphic violence nobody asked for, and a rush of safety announcements from AI labs promising their models won’t help you write malware. Meanwhile, out past all that noise, someone ran a plain old password spray campaign against Azure CLI logins at a scale that should embarrass anyone who thinks the next big threat needs a language model attached to it. Over 81 million login attempts, traced back to infrastructure tied to a hosting provider called LSHIY, hammering away at Microsoft’s command-line identity endpoint. No zero-day. No prompt injection. Just volume.

That’s the part of the cybersecurity conversation that keeps getting buried under AI headlines: the boring attacks are still the ones doing the damage, and they’re doing it because a lot of organizations still haven’t closed the door on them.

Azure cloud login screen representing the Azure CLI password spray campaign
A brute-force campaign against Azure CLI logins logged over 81 million attempts.

The Attack That Doesn’t Need a Headline

Password spraying isn’t clever. It’s the attack equivalent of trying every key on a giant ring until one turns the lock, except attackers spread the attempts across thousands of accounts so no single account trips a lockout threshold. A handful of guesses per user, rotated across a massive list of usernames, run continuously from rented or compromised infrastructure. It’s cheap, it’s automatable, and it works precisely because it’s unglamorous enough that a lot of monitoring setups aren’t tuned to catch it.

Azure CLI is a particularly juicy target because it’s a developer and automation surface, not a consumer login page. The accounts behind it often have broad permissions, service principals, and API access that a typical phishing target wouldn’t. Compromise one CLI credential and you’re not stealing a Netflix password, you’re potentially sitting inside someone’s cloud subscription with rights to spin up resources, read storage, or pivot into other services entirely.

And here’s the one-liner worth sitting with: attackers don’t need an exploit when your identity layer will hand them the keys for free.

The AI Panic Is Real. It’s Just Not the Threat Report You Needed Today

None of this is to say the AI safety conversation is misplaced. Anthropic’s release of Claude Sonnet 5 came bundled with explicit safeguards against dangerous cyber use, which is a genuinely good sign that at least some labs are building guardrails before, not after, a model gets weaponized. Contrast that with the Malwarebytes report on ChatGPT producing graphic violent imagery that caught its own researchers off guard, or the Schneier-flagged reporting on AI-driven video surveillance that lets analysts ask natural-language questions across huge volumes of footage instead of running a handful of preset searches. Both are legitimate, evolving risk categories. Surveillance capability is scaling with model capability, and that deserves scrutiny.

But none of that stopped an 81-million-attempt brute-force campaign this week. The uncomfortable truth is that most breaches still start with something an AI model has nothing to do with: a weak or reused password, no rate limiting, and no meaningful threat detection watching the identity provider’s logs. If your team’s threat model spends more energy war-gaming hypothetical AI-assisted attacks than it spends on password hygiene and login telemetry, you’re solving tomorrow’s problem while today’s is already inside your tenant.

Why Your Firewall Isn’t the Control That Matters Here

A lot of organizations still think of their firewall as the primary line of threat protection, and for a campaign like this, that’s the wrong mental model entirely. Password spraying against a cloud identity endpoint doesn’t touch your perimeter. There’s no packet to block at the edge, no port to close. The attack surface here is authentication itself, which means your firewall rules are irrelevant and your identity provider’s login policies are the whole game.

This is where defense in depth actually earns its name instead of being a slide in a vendor deck. You need layered controls at the identity layer specifically: conditional access policies that factor in location and device health, risk-based sign-in evaluation, and phishing-resistant MFA that doesn’t rely on a code an attacker can also phish. Security hardening for cloud identity isn’t a one-time project, it’s an ongoing discipline, because attackers rotate infrastructure and tactics faster than most access reviews get scheduled.

What to Actually Do About It

None of this requires exotic tooling. It requires discipline and someone actually watching the logs. Concrete steps worth putting in front of your team this week:

  • Enforce phishing-resistant MFA (FIDO2 keys or certificate-based auth) on every account with CLI, API, or service principal access, not just interactive human logins.
  • Turn on smart lockout or equivalent throttling for authentication endpoints, and confirm it actually applies to CLI and programmatic sign-ins, not just the web portal.
  • Set conditional access policies that block or challenge sign-ins from unfamiliar geographies, anonymized IPs, or infrastructure ranges associated with hosting providers rather than residential ISPs.
  • Rotate and audit service principal credentials and API keys on a real schedule, not “whenever someone remembers.”
  • Feed authentication logs, especially failed and impossible-travel sign-ins, into whatever threat detection or SIEM pipeline you already run, and alert on spray patterns (many accounts, few attempts each) rather than just single-account lockout thresholds.
  • Have an incident response playbook ready specifically for credential compromise in cloud identity, including immediate session revocation and forced re-authentication across connected services.

If any of those bullets made you wince because you know the answer is “we don’t do that consistently,” that’s the actual finding from this week’s news, not the AI headlines.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.