Tech

New Azure Active Directory password brute-forcing flaw has no fix

Enlarge (credit: Michael Dziedzic) Imagine having unlimited attempts to guess someone’s username and password without getting caught. That would make an ideal scenario for a stealthy threat actor—leaving server admins with little to no visibility into the attacker’s actions, let alone the possibility of blocking them. A newly discovered bug in Microsoft Azure’s Active Directory […]