Threat intelligence firm Huntress has recorded a 155-fold increase in password spraying attacks during the first half of 2026, with one coordinated campaign alone generating over 81 million login attempts in a two-week window. Rather than relying on traditional high-volume brute force, threat actors are systematically exploiting misconfigured multi-factor authentication (MFA) deployments and unsecured legacy authentication pathways to bypass secondary verification entirely.

The modern credential-testing playbook has shifted toward low-and-slow automation. By distributing sparse login attempts across thousands of accounts, attackers keep activity beneath conventional lockout and alert thresholds, effectively masking malicious traffic as routine background noise. Huntress analysts emphasize that the vulnerability stems from architectural drift rather than inherent MFA flaws. When organizations maintain active legacy protocols such as basic IMAP or older Exchange endpoints, attackers route authentication requests through these unprotected channels, circumventing modern conditional access rules.

In response, security teams must treat identity infrastructure as a dynamic attack surface. The immediate priority is the complete decommissioning of legacy authentication protocols across cloud, hybrid, and on-premises environments. Conditional access policies must be enforced uniformly at the protocol level to eliminate routing loopholes, and dynamic lockout thresholds should replace static rules. Without these foundational controls, even enterprise-grade MFA deployments remain exposed to automated credential campaigns.

Detecting these low-frequency attacks also requires a departure from resource-heavy monitoring stacks. Traditional commercial SIEMs and endpoint agents frequently lack the granular, real-time visibility needed to identify subtle credential-testing patterns. Organizations are increasingly adopting lightweight, agentless monitoring frameworks and open-source identity stacks to maintain continuous, auditable visibility. These transparent alternatives enable precise log correlation and anomaly detection without straining security budgets or infrastructure overhead.

The H1 2026 data confirms that static perimeter defenses and set-and-forget identity policies are obsolete. As automated threat campaigns grow more sophisticated, continuous policy auditing and protocol-level enforcement must become operational baselines. Transitioning to a zero-trust validation model is no longer a strategic initiative—it is a mandatory requirement for maintaining resilience against the next wave of credential-based intrusions.


威脅情報公司 Huntress 記錄到,2026年上半年密碼噴灑攻擊(password spraying)激增155倍,其中一項協調行動僅在兩週內便產生超過8,100萬次登入嘗試。威脅行為者不再依賴傳統的高流量暴力破解,而是系統性地利用配置錯誤的多重驗證(MFA)部署及未受保護的舊版驗證途徑,完全繞過第二重驗證。

現代的憑證測試策略已轉向 low-and-slow 自動化模式。攻擊者將稀疏的登入嘗試分散至數以千計的帳戶,使活動維持在傳統的帳戶鎖定及 alert threshold 之下,有效將惡意流量掩飾為常規的背景雜訊。Huntress 分析員強調,此漏洞源於架構配置偏離,而非 MFA 本身的缺陷。當機構繼續啟用基本 IMAP 或舊版 Exchange 端點等舊版通訊協定時,攻擊者會將驗證請求路由至這些未受保護的通道,從而繞過現代的條件式存取規則。

為應對此威脅,網絡安全團隊必須將身份基礎設施視為動態攻擊面。當務之急是全面停用雲端、混合及本地環境中的舊版驗證通訊協定。條件式存取政策必須在通訊協定層面統一執行,以消除路由漏洞,並應以 dynamic lockout threshold 取代靜態規則。若缺乏這些基礎控制措施,即使是企業級 MFA 部署,仍會暴露於自動化憑證攻擊之下。

偵測此類低頻攻擊亦需擺脫資源密集的 monitoring stack。傳統商業 SIEM 及 endpoint agent 往往缺乏識別細微憑證測試模式所需的精細度與即時可見性。機構正日益採用輕量級、agentless 的監控框架及開源 identity stack,以維持持續且可審計的可見性。這些透明的替代方案能實現精確的日誌關聯與異常偵測,同時不會對網絡安全預算或基礎設施造成沉重負擔。

2026年上半年的數據證實,靜態邊界防禦及「設定後即忘」的身份政策已過時。隨著自動化威脅行動日益複雜,持續的政策審計與通訊協定層面執行必須成為營運基準。轉向零信任驗證模型已不再是策略性倡議,而是抵禦下一波憑證入侵、維持系統韌性的強制性要求。

新聞來源 / Original News Source