Account Compromise Via Azure AD Password
The NJCCIC was recently notified of a cyber incident in which a threat actor compromised a user's account credentials by targeting the Password Hash Synchronization (PHS) login method. Azure utilizes PHS to validate credentials and authenticate users without needing an additional...