Everyone loves to blame the user. The phishing click, the “stupid” password, the person who approved the MFA prompt at 2 a.m. But look closely at this week’s security news and a different pattern emerges: attackers aren’t breaking your users — they’re breaking your trust relationships. The helpdesk. The collaboration tools. The service accounts nobody owns. And a good ipban layer at the edge is still one of the cheapest controls that actually bites back.

Microsoft just published a playbook on cross-tenant helpdesk impersonation through Teams. The Hacker News ran a webinar pitch noting that 68% of 2024 cloud breaches involved non-human identities. Tycoon 2FA splintered and its kits are now reused across a phishing cottage industry. And Mirai’s Nexcorium variant is still harvesting TBK DVRs through a year-old CVE. Different stories, same lesson: the perimeter you thought you retired is the one doing the most work.

The Helpdesk Is The New Domain Admin

Microsoft’s write-up on cross-tenant helpdesk impersonation is worth reading twice. The attack isn’t clever in a technical sense. Threat actors abuse external Teams collaboration, pose as IT support, and talk a user into granting remote access. From there they use legitimate admin tooling — Quick Assist, RMM agents, PowerShell — to move laterally and exfiltrate data. Nothing exotic. Nothing a signature catches.

Why does it work? Because your organization has normalized outside entities poking at your users through sanctioned channels. Teams federation, guest access, Zoom, Slack Connect — they all look like productivity. To an attacker they look like an unguarded front door with a welcome mat that says “IT Support Here.”

The uncomfortable truth: your helpdesk already has domain-admin-equivalent influence over end users. Anyone who can successfully impersonate it gets that power for free.

Non-Human Identities Are The Real Insider Threat

For every human in your org there are 40 to 50 automated credentials floating around. Service accounts. API tokens. OAuth grants nobody revoked when the intern left. AI agent connections somebody spun up during a hackathon.

When 68% of cloud breaches trace back to compromised non-human identities, the “train your users” advice becomes almost beside the point. The ghost identities don’t click phishing links. They don’t need to. They sit there with stale permissions, reachable from the internet, waiting for someone to enumerate them.

Where these things hide

If you’ve never done an honest inventory, start here:

  1. OAuth grants in Entra ID and Google Workspace — sort by “last used” and prepare to wince.
  2. CI/CD runners with long-lived cloud keys pasted into environment variables.
  3. SaaS-to-SaaS integrations that a single employee authorized three reorganizations ago.
  4. Legacy service accounts with passwords older than most interns.

None of those show up in your EDR dashboard. None of them will call the helpdesk. They just quietly authenticate from somewhere they shouldn’t.

Why IPBan Still Earns Its Keep In 2026

Here’s where the stories converge. The Mirai Nexcorium variant chewing through TBK DVRs via CVE-2024-3721 isn’t using AI. It’s using SSH and web login brute force against devices exposed to the internet. The Grinex exchange hack, whatever the geopolitical framing, almost certainly started with credential abuse against an exposed endpoint. Tycoon 2FA’s successors still need infrastructure — and that infrastructure shows up in logs before it shows up in a vendor threat feed.

An ipban-style control at your edge does three unglamorous things very well:

  • Shuts down brute-force attempts against RDP, SSH, SMTP, and web logins before they cost you a lockout storm.
  • Blocks known-malicious ASNs, TOR exits, and freshly-seen scanner ranges without waiting for a SIEM rule to be tuned.
  • Produces the authentication-attempt signal that your SOC actually needs to correlate with identity telemetry.

Is it a silver bullet? No. Is it 2006 technology? Also no — modern IPBan Pro integrates live reputation data, aggregates failed auth across your whole fleet, and shares bans across your estate so a probe against one server blocks the attacker everywhere. That’s cheap leverage. In a year where helpdesks get impersonated and OAuth tokens get stolen, closing the dumb-loud attack paths lets your humans focus on the quiet ones.

Microsoft advisory on cross-tenant helpdesk impersonation intrusions
Microsoft’s breakdown of helpdesk impersonation shows attackers leaning on trust, not exploits.

A Concrete Plan You Can Run This Quarter

Stop reading threat intel for five minutes and do the work. Here’s a sequence that addresses the week’s headlines without needing a new budget cycle:

Lock down external collaboration. In Teams, restrict external access to an allow-list of federated tenants. Kill anonymous join for meetings that contain sensitive material. Disable the ability for unverified external users to initiate chats with your staff. Microsoft’s own guidance covers the toggles — you just have to flip them.

Audit and expire non-human identities. Pull every OAuth grant, every service principal, every API key. Anything unused in 90 days goes into a revocation queue. Anything with broad scopes (Mail.ReadWrite, Files.ReadWrite.All, Directory.ReadWrite.All) gets a named human owner or it dies.

Put brute-force protection in front of anything internet-facing. Not just RDP. Your VPN portal, your Exchange endpoint, your self-hosted apps, your jump boxes. Deploy IPBan Pro on Windows and Linux fleets, feed it the auth logs, and let it do the triage your analysts shouldn’t have to do by hand. The firewall-level blocks stop brute-force traffic from ever reaching your identity provider, which means fewer lockouts, fewer false positives in your SIEM, and fewer 3 a.m. pages.

Patch the loud CVEs even when they’re boring. Protobuf.js RCE. TBK DVR command injection. EoL TP-Link routers. These don’t make the board deck, but they are what’s actually in the wild. If it’s exposed and exploitable, it gets patched this sprint or it gets isolated.

The Thread Nobody Wants To Admit

The connective tissue across every story this week is the same: defenders keep investing in the sexy layer while attackers keep winning at the boring one. Fancy EDR can’t see a helpdesk impersonation that rides on legitimate tooling. Cloud CSPM doesn’t catch a stale OAuth grant that’s technically authorized. Phishing training won’t help if the user thinks they’re talking to their own IT team.

What does help is layering controls so each one compensates for the others’ blind spots. Edge-level IP banning isn’t competing with your identity platform or your EDR — it’s filling the gap where they can’t see. When a brute-force wave starts testing your VPN from 400 IPs across residential proxies, your identity platform sees it as “users struggling to log in.” Your firewall sees it as traffic. An ipban layer sees it as an attack and acts in seconds.

That’s the point. Cheap, fast, automatic, and always on. In a year where attackers are getting creative about trust, the smartest defense is often the one that doesn’t try to be clever at all.

Frequently Asked Questions

Does IP banning still matter if attackers use residential proxies and rotating infrastructure?
Yes — just not the way it did in 2015. Modern brute-force protection correlates failed auth across your fleet, shares bans in near-real-time, and incorporates reputation feeds that flag residential proxy ranges associated with abuse. A single IP may rotate, but the behavioral pattern and the proxy network’s reputation persist long enough to block most attempts.
If 68% of cloud breaches involve non-human identities, why bother with firewall-level controls?
Because the same attackers who abuse service accounts also scan your perimeter to find them. Edge controls like IPBan Pro reduce the noise and surface the real signals faster, giving your identity team fewer false positives to chase. The two layers reinforce each other — you need both.
How do I justify deploying IP banning when the C-suite only wants to hear about AI security?
Frame it in dollars. Every brute-force attempt blocked at the firewall is one that doesn’t hit your identity platform’s per-auth licensing, doesn’t trigger a lockout that generates a helpdesk ticket, and doesn’t eat SOC analyst time. IPBan-style controls typically pay for themselves on ticket reduction alone before you even count the breach prevention.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.