Connect with us

Technology

Guardz Uncovers Sophisticated Campaign Exploiting Legacy Authentication in Microsoft Entra ID

Published

on

The Guardz Research Unit uncovered a coordinated cyber campaign using outdated login methods to bypass MFA and infiltrate cloud environments by attempting to exploit basic authentication protocols 

MIAMI, May 7, 2025 /PRNewswire/ — Guardz, the cybersecurity company empowering Managed Service Providers (MSPs) and IT professionals to protect small businesses with AI-native unified detection and response, today disclosed its discovery of an advanced attack campaign exploiting legacy authentication protocols in Microsoft Entra ID. Uncovered by the Guardz Research Unit (GRU), the campaign was active between March 18 and April 7, 2025, and shows how outdated authentication methods, particularly BAV2ROPC, continue to be exploited by threat actors to bypass modern identity protection systems, including Multi-Factor Authentication (MFA) and Conditional Access Policies.

The campaign has since subsided, but Guardz warns that vulnerability continues to exist in many environments, posing a critical risk to organizations that have not yet fully modernized their authentication frameworks. Sectors that were identified as being disproportionately targeted by this vulnerability include financial services, healthcare, manufacturing, and technology services.

“This campaign is a wake-up call—not just about one vulnerability, but about the broader need to retire outdated technologies that no longer serve today’s threat landscape,” said Dor Eisner, CEO and Co-Founder of Guardz. “At Guardz, we’re focused on helping small businesses and the MSPs that serve them stay ahead of evolving attacks by identifying hidden risks before they’re exploited.”

Guardz detected over 9,000 suspicious login attempts from distributed IP addresses, primarily originating in Eastern Europe and the Asia-Pacific region, indicating a globally orchestrated effort. Attackers leveraged automation, IP rotation, and advanced tooling to probe security controls and gain unauthorized access to cloud resources, particularly Exchange Online.

The attack unfolded in two major phases:

Initialization (March 18-20): Low-intensity probing with approximately 2,709 attempts per day.Sustained Attack (March 21-April 3): Spiking to over 6,444 attempts per day – a 138% increase – marking a move to aggressive exploitation.

Guardz tracked this progression using new AI-driven research methods and internal systems designed to continuously hunt for anomalous behavior and active threat campaigns on the dark web. The company’s AI agents executed thousands of actions in tandem with human GRU researchers, identifying patterns across IPs, geographies, and attack tools.

The campaign zeroed in on Basic Authentication Version 2 – Resource Owner Password Credential (BAV2ROPC), a behind-the-scenes compatibility mechanism in Entra ID that allows legacy applications to authenticate using usernames and passwords. Unlike modern, interactive login flows that enforce MFA and security checks, BAV2ROPC operates non-interactively and bypasses MFA, Conditional Access Policies, and login alerts and user presence verification.

Guardz urges all organizations to immediately mitigate risks from legacy authentication by auditing and disabling outdated protocols, enforcing modern authentication and MFA across all accounts, implementing conditional access policies to block unsupported flows like ROPC, and closely monitoring for unusual login activity or failed authentication patterns.

Recognizing that small businesses often lack the in-house teams and infrastructure available to larger enterprises, Guardz bridges this gap with its AI-powered cybersecurity platform that delivers identity protection, email security, threat detection, and automated incident response, purpose-built for the needs of small organizations.

To explore Guardz’s findings on the legacy authentication attack campaign and how its platform defends against such threats, read the full research blog here.

About Guardz

Guardz provides MSPs and IT professionals with an AI-powered cybersecurity platform designed to secure and insure SMBs against cyberattacks. The Guardz platform offers automatic detection and response, protecting users, emails, devices, cloud directories, and data. By simplifying cybersecurity management, Guardz enables businesses to focus on growth without being bogged down by security complexities. The company’s scalable and cost-effective pricing model ensures comprehensive protection for all digital assets, facilitating rapid deployment and business expansion.

Media Contact
Allison Grey
allison@headline.media
+1 323 283 8176

 

View original content:https://www.prnewswire.com/news-releases/guardz-uncovers-sophisticated-campaign-exploiting-legacy-authentication-in-microsoft-entra-id-302448704.html

SOURCE Guardz

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

Bill Faust Named Consulting Magazine Top Consultant of the Year in Industry Specialization

Published

on

By

Impact Advisors Leader Recognized for Expertise in Healthcare IT Implementation

CHICAGO, April 22, 2026 /PRNewswire-PRWeb/ — Impact Advisors, a leading healthcare management consulting firm, is proud to announce that Bill Faust, Managing Director, has been named a Top Consultant of the Year by Consulting Magazine in the category of Industry Specialization. This prestigious award honors consultants who demonstrate deep domain expertise and deliver exceptional value to clients within their field.

“Bill’s recognition as a Top Consultant of the Year is a testament to his deep industry expertise and unwavering commitment to client success.” -Andy Smith, managing partner and co-founder of Impact Advisors

Faust brings more than 28 years of healthcare IT experience, with a distinguished track record leading large-scale, complex implementations for both ambulatory and acute care organizations. Over the past 25 years, he has held progressive leadership roles supporting major Epic and Oracle initiatives, helping healthcare systems successfully navigate digital transformation and achieve measurable outcomes.

In his role at Impact Advisors, Faust leads the firm’s EHR Implementation & Support practice, where he is responsible for driving strategy, delivery excellence, and client success across some of the most complex healthcare IT programs in the country. His ability to combine deep technical knowledge with strong executive communication has enabled him to build trusted relationships with clients and vendor partners alike.

“Bill’s recognition as a Top Consultant of the Year is a testament to his deep industry expertise and unwavering commitment to client success,” said Andy Smith, managing partner and co-founder of Impact Advisors. “He consistently delivers high-impact results for our clients while helping advance the healthcare industry through his thoughtful, strategic leadership. Bill joined our team as our ninth colleague, and we’re fortunate to have had his guidance for all these years.”

Consulting Magazine’s Top Consultants awards recognize outstanding professionals who have made significant contributions to the consulting profession and their clients. The Industry Specialization category specifically highlights consultants who have demonstrated exceptional depth of knowledge and impact within a defined sector.

Faust’s recognition underscores Impact Advisors’ continued leadership in healthcare consulting and its commitment to delivering innovative, high-quality solutions that improve patient care and operational performance.

About Impact Advisors

Impact Advisors is a leading healthcare management consulting firm offering a comprehensive suite of technology-enabled performance improvement solutions that deliver measurable and sustainable value for clients. Our commitment to excellence has earned Best in KLAS® recognition for 19 consecutive years, and our distinctive culture has been named a “Best Place to Work” by Modern Healthcare for 16 years. Learn more at www.impact-advisors.com.

Media Contact

Catherine Povalitis, Impact Advisors, 1 815-282-9976, cpovalitis@chartwellagency.com, https://www.impact-advisors.com/

View original content to download multimedia:https://www.prweb.com/releases/bill-faust-named-consulting-magazine-top-consultant-of-the-year-in-industry-specialization-302750670.html

SOURCE Impact Advisors

Continue Reading

Technology

Hewlett Foundation President: Philanthropy Must Bridge AI Governance Gap Between Washington and Silicon Valley

Published

on

By

Amber D. Miller makes the case for philanthropy and civil society to protect critical infrastructure and deliver broad benefits.

SAN FRANCISCO, April 22, 2026 /PRNewswire/ — As conversations between Washington and Silicon Valley about AI policy grow more contentious, Hewlett Foundation President Amber D. Miller calls on philanthropy to step up. In a new op-ed published by RealClearPolicy, Miller argues that governments and industry can’t close America’s AI governance gap alone, but independent institutions and philanthropy can help bridge the divide.

Drawing on her background as a physicist, Miller advocates for a practical, non-ideological approach to AI governance focused on protecting critical infrastructure, preventing strategic technological surprise, and keeping people safe while fostering innovation.

“Much of America’s critical infrastructure is highly distributed and deeply vulnerable, and its protection is dangerously under-resourced. The Hewlett Foundation wants to maximize the public benefits of emerging technologies while proactively mitigating their risks.”

To address these challenges, the Hewlett Foundation recently announced $10 million in exploratory grants to support the security of emerging technologies, including AI, biotechnology, and quantum computing.

Major grants were awarded to Stanford University’s Hoover Institution for its Tech Futures Lab, which focuses on anticipating technological surprises and enhancing U.S. resilience and Vanderbilt University’s Institute for National Security for its Wicked Problems Lab, which is building defenses against synthetic information warfare like deepfakes.

Former Secretary of State Condoleezza Rice, the director of the Hoover Institution, highlighted the importance of integrating security into innovation: “Innovation is key to national security…. Innovators will have more valuable, more marketable products if they build security into it at the front end.”

Other grantees include, the AI Now Institute, Aspen Institute, Atlantic Council, Carnegie Endowment for International Peace, Council on Foreign Relations, Georgetown University, Global Network Initiative, Institute for Security and Technology, Observer Research Foundation America, RAND, and Sentinel Bio.

Miller calls on others to join Hewlett, writing, “America has led every major technological era of the modern age, helping usher in significant discoveries that have benefited communities both here and around the world. Whether it continues to lead will depend not only on breakthroughs in labs, but on whether innovation earns public trust and delivers broad benefits. Philanthropy, with its long-term focus and commitment to charitable good, can do much to help.”

For more, read the op-ed and grant announcement: https://hewlett.org/americas-ai-governance-gap-needs-independent-oversight/ 

View original content to download multimedia:https://www.prnewswire.com/news-releases/hewlett-foundation-president-philanthropy-must-bridge-ai-governance-gap-between-washington-and-silicon-valley-302750841.html

SOURCE The Hewlett Foundation

Continue Reading

Technology

Hyperscale Data Sees Rising Demand Across Defense Portfolio Amid Heightened Global Activity

Published

on

By

LAS VEGAS, April 22, 2026 /PRNewswire/ — Hyperscale Data, Inc. (NYSE American: GPUS), an artificial intelligence (“AI”) data center company anchored by Bitcoin (“Hyperscale Data” or the “Company”), today announced that its wholly-owned subsidiary Gresham Worldwide, Inc., which is expected to be merged with another wholly owned subsidiary of the Company called Ballista Group, Inc., and the related party TurnOnGreen, Inc. (the “Defense Systems Group”), are actively supporting the expected increase in global defense production through its integrated portfolio of high-performance defense engineering and manufacturing subsidiaries.

The Defense Systems Group operates as an integrated engineering and manufacturing platform serving defense, aerospace, and industrial markets, delivering mission-critical electronics, radio frequency (“RF”) systems, power platforms, and advanced control technologies across the full lifecycle, from design through long-term sustainment. 

Recent global events, including but not limited to the ongoing conflicts in the Middle East and Ukraine, have contributed to increased demand signals across defense and mission-critical infrastructure supply chains. Management of the Defense Systems Group has observed a measurable uptick in inbound inquiries, program discussions and order flow across the group’s core product lines, particularly in:

RF and microwave systems supporting radar and electronic warfare;Power systems and ruggedized electronics for defense and mobility platforms; andTest, validation, and simulation technologies for mission-critical environments.

“These are environments where failure is not an option,” said Milton “Todd” Ault III, Executive Chairman of Hyperscale Data. He added that “The Defense Systems Group was assembled to deliver precision-engineered solutions for exactly these mission-critical applications, and we are seeing that demand accelerate in real time.” Further, Mr. Ault stated that “The group’s combination of deep engineering expertise, advanced manufacturing capabilities, and a global operational footprint provides a strong foundation to support long-term growth across defense, aerospace, and other mission-critical technology sectors.

The Defense Systems Group platform supports highly regulated and security-sensitive programs, operating under certifications including ISO, AS9100, and ITAR compliance, and serves customers across defense, aerospace, and critical infrastructure sectors globally. 

“As geopolitical conditions evolve, supply chains for advanced electronics and defense-related technologies are becoming increasingly constrained,” stated William Horne, Chief Executive Officer of Hyperscale Data. “The Defense Systems Group collectively provides a vertically integrated platform supporting advanced defense electronics, power systems, RF and microwave components, and precision-engineered subsystems, positioning the organization to support current and emerging demand across multiple strategic defense programs.”

While the Company continues to monitor global developments, management of the Defense Systems Group believes that sustained demand for mission-critical electronics, ruggedized power systems, and secure infrastructure technologies could present potential opportunities across the Defense Systems Group.

For more information on Hyperscale Data and its subsidiaries, Hyperscale Data recommends that stockholders, investors and any other interested parties read Hyperscale Data’s public filings and press releases available under the Investor Relations section at hyperscaledata.com or available at www.sec.gov.

About Hyperscale Data, Inc.

Through its wholly owned subsidiary Sentinum, Inc., Hyperscale Data owns and operates a data center at which it mines digital assets and offers colocation and hosting services for the emerging AI ecosystems and other industries. Hyperscale Data’s other wholly owned subsidiary, Ault Capital Group, Inc. (“ACG”), is a diversified holding company pursuing growth by acquiring undervalued businesses and disruptive technologies with a global impact.

Hyperscale Data currently expects the divestiture of ACG (the “Divestiture”) to occur in the second quarter of 2027. Upon the occurrence of the Divestiture, the Company would be an owner and operator of data centers to support high-performance computing services, as well as a holder of the digital assets. Until the Divestiture occurs, the Company will continue to provide, through ACG and its wholly and majority-owned subsidiaries and strategic investments, mission-critical products that support a diverse range of industries, including an AI software platform, equipment rental services, defense/aerospace, industrial, automotive, medical/biopharma and hotel operations. In addition, ACG is actively engaged in private credit and structured finance through a licensed lending subsidiary. Hyperscale Data’s headquarters are located at 11411 Southern Highlands Parkway, Suite 190, Las Vegas, NV 89141.

On December 23, 2024, the Company issued one million (1,000,000) shares of a newly designated Series F Exchangeable Preferred Stock (the “Series F Preferred Stock”) to all common stockholders and holders of the Series C Preferred Stock on an as-converted basis. The Divestiture will occur through the voluntary exchange of the Series F Preferred Stock for shares of Class A Common Stock and Class B Common Stock of ACG (collectively, the “ACG Shares”). The Company reminds its stockholders that only those holders of the Series F Preferred Stock who agree to surrender such shares, and do not properly withdraw such surrender, in the exchange offer through which the Divestiture will occur, will be entitled to receive the ACG Shares and consequently be shareholders of ACG upon the occurrence of the Divestiture.

Forward-Looking Statements

This press release contains “forward-looking statements” within the meaning of Section 27A of the Securities Act of 1933, as amended, and Section 21E of the Securities Exchange Act of 1934, as amended. These forward-looking statements generally include statements that are predictive in nature and depend upon or refer to future events or conditions, and include words such as “believes,” “plans,” “anticipates,” “projects,” “estimates,” “expects,” “intends,” “strategy,” “future,” “opportunity,” “may,” “will,” “should,” “could,” “potential,” or similar expressions. Statements that are not historical facts are forward-looking statements. Forward-looking statements are based on current beliefs and assumptions that are subject to risks and uncertainties.

Forward-looking statements speak only as of the date they are made, and the Company undertakes no obligation to update any of them publicly in light of new information or future events. Actual results could differ materially from those contained in any forward-looking statement as a result of various factors. More information, including potential risk factors, that could affect the Company’s business and financial results are included in the Company’s filings with the U.S. Securities and Exchange Commission, including, but not limited to, the Company’s Forms 10-K, 10-Q and 8-K. All filings are available at www.sec.gov and on the Company’s website at hyperscaledata.com.

View original content to download multimedia:https://www.prnewswire.com/news-releases/hyperscale-data-sees-rising-demand-across-defense-portfolio-amid-heightened-global-activity-302750842.html

SOURCE Hyperscale Data Inc.

Continue Reading

Trending