Security Briefing | July 01, 2026 - Azure CLI Hit by 81M Password Spray Attempts, Citrix Patches Six NetScaler Flaws, 900+ Oracle EBS Instances Still Exposed
A massive automated password spray campaign targeting Azure CLI made over 81 million login attempts and compromised at least 78 accounts between June 12-26. Citrix released patches for six NetScaler vulnerabilities including an HTTP/2 Bomb attack vector and a CitrixBleed-style information disclosure flaw. Meanwhile, over 900 Oracle E-Business Suite instances remain exposed to ongoing active exploitation of a critical unauthenticated RCE flaw.
By EACA Summit Content Team

1. Massive Azure CLI Password Spray Campaign Compromises 78+ Microsoft Accounts
A large-scale, automated password spray attack targeting Microsoft's Azure CLI compromised at least 78 accounts out of over 81 million login attempts. The activity, originating from an IPv6 range controlled by LSHIY LLC, was detected between June 12-26, 2026. Huntress researchers identified the campaign, which underscores the risk of weak credentials in cloud environments.
Verified Facts
- Over 81 million password spray attempts were made against Azure CLI
- At least 78 Microsoft accounts were compromised
- Attack originated from IPv6 range 2a0a:d683::/32 (AS32167, LSHIY LLC)
- Campaign active between June 12 and June 26, 2026
Evidence
- Huntress research report
- IPv6 range attribution to LSHIY LLC
Impact
Organizations using Azure CLI should enforce multi-factor authentication and monitor for anomalous login attempts to prevent account takeover.
Confidence Level: High
Sources The Hacker News | SecurityWeek
2. Citrix Patches Six NetScaler Flaws Including HTTP/2 Bomb Attack

Citrix released security updates addressing six vulnerabilities in NetScaler ADC and Gateway, including a critical flaw (CVE-2026-8451, CVSS 8.8) that could allow arbitrary file reads or denial-of-service. The updates also fix an HTTP/2 Bomb attack vector and a high-severity information disclosure bug similar to CitrixBleed.
Verified Facts
- Six vulnerabilities patched in NetScaler ADC and Gateway
- CVE-2026-8451 has a CVSS score of 8.8 and involves insufficient input validation
- Patches address HTTP/2 Bomb attack and CitrixBleed-style disclosure
- Citrix urges immediate patching
Evidence
- CVE-2026-8451
- Citrix security advisory
Impact
Defenders should prioritize patching NetScaler appliances to prevent file disclosure and DoS attacks, especially given active exploitation of similar flaws.
Confidence Level: High
Sources The Hacker News | SecurityWeek
3. Oracle E-Business Suite Update: 900+ Instances Still Exposed to Ongoing Attacks
New data confirms that over 900 Oracle E-Business Suite instances remain exposed online, with active scanning and exploitation continuing against the critical unauthenticated RCE vulnerability first reported June 30. Threat actors are actively targeting unpatched systems, and the attack surface remains dangerously large.
Verified Facts
- Over 900 Oracle EBS instances are exposed online
- Ongoing attacks exploit a critical security flaw
- Vulnerability allows unauthenticated remote code execution
- Patches are available from Oracle
Evidence
- Oracle security advisory
- Attack activity observed in the wild
Impact
Organizations running Oracle EBS should immediately patch and restrict access to prevent remote compromise and data breaches. The continued exposure of 900+ instances suggests patching rates remain critically low.
Confidence Level: High
Sources BleepingComputer | The Hacker News
All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.



