:

PASSWORD SPRAYING ATTACKS SPIKE 155X IN 2026

SECURITY DESK1 MIN READ
WED, AUG 19, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Security firm Huntress detected a 155-fold increase in password spraying attacks during the first half of 2026, with one campaign generating over 81 million login attempts in just two weeks.

The surge exploits vulnerabilities in legacy authentication systems and gaps in multifactor authentication (MFA) policies that leave certain login flows unprotected. Password spraying attacks work by systematically attempting common passwords across many user accounts, rather than targeting individual accounts with multiple passwords. This approach often bypasses rate-limiting defenses designed to stop brute-force attacks. Huntress found that attackers successfully leveraged unprotected authentication endpoints where MFA policies either didn't apply or were incompletely implemented. Organizations with inconsistent MFA rollouts across different login paths proved particularly vulnerable. The findings underscore a critical security gap: implementing MFA across all authentication flows, not just primary login portals, is essential. Legacy systems that predate modern security standards remain a significant risk factor for enterprises managing mixed infrastructure. Security experts recommend auditing all login pathways for MFA coverage, enforcing conditional access policies, and monitoring for anomalous login patterns as immediate mitigation steps.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A casual domain registration escalated into international tension when a developer's lighthearted purchase became entangled in balloon tracking infrastructure and cross-border disputes.

JUST NOWAI Desk

Roblox has agreed to implement privacy changes after Australia's eSafety commissioner discovered adults could contact children without parental consent on the gaming platform. The regulator said verifiable safety measures are critical to the service's viability.

JUST NOWSecurity Desk

Healthcare software company CareCloud confirmed a cyberattack compromised medical records for 3.7 million patients, marking one of the largest healthcare data breaches in the U.S. this year.

1H AGOSecurity Desk

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has alerted organizations to a critical remote code execution vulnerability in Windows Internet Key Exchange (IKE) Service Extensions that hackers are actively exploiting.

5H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.