Connect with us

Technology

Guardz Uncovers Sophisticated Campaign Exploiting Legacy Authentication in Microsoft Entra ID

Published

on

The Guardz Research Unit uncovered a coordinated cyber campaign using outdated login methods to bypass MFA and infiltrate cloud environments by attempting to exploit basic authentication protocols 

MIAMI, May 7, 2025 /PRNewswire/ — Guardz, the cybersecurity company empowering Managed Service Providers (MSPs) and IT professionals to protect small businesses with AI-native unified detection and response, today disclosed its discovery of an advanced attack campaign exploiting legacy authentication protocols in Microsoft Entra ID. Uncovered by the Guardz Research Unit (GRU), the campaign was active between March 18 and April 7, 2025, and shows how outdated authentication methods, particularly BAV2ROPC, continue to be exploited by threat actors to bypass modern identity protection systems, including Multi-Factor Authentication (MFA) and Conditional Access Policies.

The campaign has since subsided, but Guardz warns that vulnerability continues to exist in many environments, posing a critical risk to organizations that have not yet fully modernized their authentication frameworks. Sectors that were identified as being disproportionately targeted by this vulnerability include financial services, healthcare, manufacturing, and technology services.

“This campaign is a wake-up call—not just about one vulnerability, but about the broader need to retire outdated technologies that no longer serve today’s threat landscape,” said Dor Eisner, CEO and Co-Founder of Guardz. “At Guardz, we’re focused on helping small businesses and the MSPs that serve them stay ahead of evolving attacks by identifying hidden risks before they’re exploited.”

Guardz detected over 9,000 suspicious login attempts from distributed IP addresses, primarily originating in Eastern Europe and the Asia-Pacific region, indicating a globally orchestrated effort. Attackers leveraged automation, IP rotation, and advanced tooling to probe security controls and gain unauthorized access to cloud resources, particularly Exchange Online.

The attack unfolded in two major phases:

Initialization (March 18-20): Low-intensity probing with approximately 2,709 attempts per day.Sustained Attack (March 21-April 3): Spiking to over 6,444 attempts per day – a 138% increase – marking a move to aggressive exploitation.

Guardz tracked this progression using new AI-driven research methods and internal systems designed to continuously hunt for anomalous behavior and active threat campaigns on the dark web. The company’s AI agents executed thousands of actions in tandem with human GRU researchers, identifying patterns across IPs, geographies, and attack tools.

The campaign zeroed in on Basic Authentication Version 2 – Resource Owner Password Credential (BAV2ROPC), a behind-the-scenes compatibility mechanism in Entra ID that allows legacy applications to authenticate using usernames and passwords. Unlike modern, interactive login flows that enforce MFA and security checks, BAV2ROPC operates non-interactively and bypasses MFA, Conditional Access Policies, and login alerts and user presence verification.

Guardz urges all organizations to immediately mitigate risks from legacy authentication by auditing and disabling outdated protocols, enforcing modern authentication and MFA across all accounts, implementing conditional access policies to block unsupported flows like ROPC, and closely monitoring for unusual login activity or failed authentication patterns.

Recognizing that small businesses often lack the in-house teams and infrastructure available to larger enterprises, Guardz bridges this gap with its AI-powered cybersecurity platform that delivers identity protection, email security, threat detection, and automated incident response, purpose-built for the needs of small organizations.

To explore Guardz’s findings on the legacy authentication attack campaign and how its platform defends against such threats, read the full research blog here.

About Guardz

Guardz provides MSPs and IT professionals with an AI-powered cybersecurity platform designed to secure and insure SMBs against cyberattacks. The Guardz platform offers automatic detection and response, protecting users, emails, devices, cloud directories, and data. By simplifying cybersecurity management, Guardz enables businesses to focus on growth without being bogged down by security complexities. The company’s scalable and cost-effective pricing model ensures comprehensive protection for all digital assets, facilitating rapid deployment and business expansion.

Media Contact
Allison Grey
allison@headline.media
+1 323 283 8176

 

View original content:https://www.prnewswire.com/news-releases/guardz-uncovers-sophisticated-campaign-exploiting-legacy-authentication-in-microsoft-entra-id-302448704.html

SOURCE Guardz

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

BlueNexus Technologies Unveils AquaX Hub at SIWW 2026 — AI Autonomous Operations Extended to Legacy Water Assets

Published

on

By

SINGAPORE, June 21, 2026 /PRNewswire/ — At Singapore International Water Week (SIWW) 2026, BlueNexus Technologies unveiled the global debut of AquaX Hub™ — a compact plug-and-play edge device that brings full AI-powered autonomous operation to standalone water equipment and legacy treatment plants. The launch drew sustained engagement from utilities, industrial operators and engineering firms.

The water sector confronts converging pressures: aging infrastructure, a critical shortage of skilled technicians, and relentless operational cost escalation. AquaX Hub™ answers these directly — extending the AI autonomous operation already proven plant-wide by AquaX Robot™ to a single asset, and delivering comparable monitoring and operational management without a control-system overhaul.

“The industry cannot hire its way out of this problem,” said Jack Zhang, CEO of BlueNexus Technologies. “AI autonomous operation is no longer a future concept — the barrier to entry is gone.”

The AquaX Ecosystem

BlueNexus has built the industry’s first fully integrated AI autonomous water operation platform, spanning three complementary pillars:

AquaX Robot™ is the flagship plant-wide AI agent, built on large language models with proprietary vision, acoustic and infrared multimodal sensing. It optimizes treatment processes 24/7 and predicts equipment failures. Live deployments show up to 90% reduction in on-site staffing, a 50% drop in equipment breakdowns, and approximately 35% lower O&M costs.

AquaX Hub™, making its global debut at SIWW 2026, is a lightweight edge terminal extending that capability to any water system. With an independent local processing module, it monitors and inspects equipment through multimodal sensing and runs a self-contained processing loop. The device integrates seamlessly with existing SCADA, cloud and enterprise platforms via standardized APIs.

i-WaterHub™, the company’s standardized modular treatment plant, operated autonomously by AquaX Robot, delivers 2,500 to 40,000 m³/day for municipal and industrial applications.

Market Momentum

SIWW 2026 convened nearly 500 exhibitors from over 65 countries. BlueNexus has identified priority markets for AquaX Hub™ in Southeast Asia, the Middle East and Africa. “The conversations this week have already translated into concrete business opportunities and we expect rapid deployment in the coming months.” Zhang confirmed.

About BlueNexus Technologies

BlueNexus Technologies is a Singapore-based water-technology company building intelligent, AI-operated systems for the world’s most water-intensive industries. We design and deliver modular water treatment infrastructure that is smarter to run, faster to deploy, and built to operate autonomously.

Web: www.bluenexus.tech

View original content to download multimedia:https://www.prnewswire.com/apac/news-releases/bluenexus-technologies-unveils-aquax-hub-at-siww-2026–ai-autonomous-operations-extended-to-legacy-water-assets-302805849.html

SOURCE BlueNexus Technologies

Continue Reading

Technology

VIVATECH 2026 CELEBRATES ITS 10TH ANNIVERSARY WITH A RECORD EDITION SURPASSING 200,000 VISITORS

Published

on

By

With the presence of Emmanuel Macron and Narendra Modi, Prime Minister of India

PARIS, June 20, 2026 /CNW/ — From June 17 to 20, 2026 at Paris Porte de Versailles, VivaTech celebrated its 10th edition, surpassing the exceptional milestone of 200,000 visitors from 165 nationalities, with more than 15,000 startups present, 1,155 speakers and over 5 billion cumulative impressions on social media. Europe’s largest tech and innovation event has reached a new dimension, consolidating its status as an unmissable global gathering.

Exceptional speakers

VivaTech welcomed the greatest figures in global tech: Jeff Bezos (Amazon & Blue Origin), Dave Limp (Blue Origin), Bernard Arnault (LVMH), Henna Virkkunen (European Commission), Ekaterina Zaharieva (European Commission). Germany, Country of the Year 2026, was represented by a ministerial delegation, while India, AI Country Partner 2026, was led by Prime Minister Narendra Modi, as a continuation of the AI Summit in New Delhi.

Innovation and business at the heart of the event

More than 4,500 exhibitors, 61% of whom were international, showcased their latest innovations. Among the standout innovations: the smart contact lens by XPANCEO, the thought-controlled humanoid robot by Unitree x HABS, and the 3D-printed resorbable implants by Lattice Medical. New formats such as the Business Plaza and Investors Office Hours further accelerated business connections.

The VivaTech x Bloomberg Awards

For the first time, VivaTech presented the VivaTech x Bloomberg Awards, recognising the most influential figures in global tech, including Sir Tim Berners-Lee (Visionary Award), Joe Tsai (Leadership Award) and Yann LeCun (Momentum Award).

Innovation open to all

VivaTech also took over the Champs-Élysées on June 14th for an open-air technology showcase, before opening its doors to the general public on June 20th with astronaut Thomas Pesquet as guest star.

“This 10th edition was not a celebration of the 9 previous years, but the opening of a new decade full of promise.” — Maurice Lévy, Michèle Benbunan & François Bitouzet, VivaTech

See you from June 16 to 19, 2027 at Paris Expo Porte de Versailles for VivaTech 2027!

About VivaTech

VivaTech accelerates innovation by connecting startups, tech leaders, major companies, and investors responding to our world’s biggest challenges.  

Each year, over four exciting days in Paris, VivaTech creates Europe’s biggest startup and tech event, exploring the most disruptive topics in tech with world-premiere demos, launches, and conferences in a collaborative ecosystem. This is where business meets innovation. Join us for the eleventh edition of VivaTech 16-19 June 2027.

For more information go to our website at https://vivatech.com/media or follow us on social media @VivaTech.

Contact
press@vivatechnology.com 

Logo: https://mmx.prnewswire.com/media/MS1865564/VT_LOGO_EN.jpg
Photo : https://mmx.prnewswire.com/media/MS1869778/VivaTech_2026.jpg

View original content to download multimedia:https://www.prnewswire.com/news-releases/vivatech-2026-celebrates-its-10th-anniversary-with-a-record-edition-surpassing-200-000-visitors-302805827.html

SOURCE VivaTech

Continue Reading

Technology

Pope Leo XIV embraces paediatric patients at CNAO in Pavia

Published

on

By

PAVIA, Italy, June 20, 2026 /PRNewswire/ — The National Center for Oncological Hadrontherapy (CNAO) served as the first stop today during Pope Leo XIV’s pastoral visit to the city of Pavia. His choice to begin his journey at this center reflects a profound commitment to fostering meaningful dialogue between advanced scientific progress and the alleviation of human suffering.

CNAO President Gianluca Vago and General Manager Sandro Rossi received His Holiness, illustrating the center’s distinctive capabilities. CNAO stands out as a unique reality in Italy, remaining one of the very few facilities worldwide capable of delivering hadrontherapy using both protons and carbon ions. The technological core of the facility is its synchrotron, a subatomic particle accelerator that generates ultra-high-precision beams to treat complex, inoperable and radioresistant tumours. This cutting-edge technology allows for the targeted eradication of diseased cells while meticulously preserving surrounding healthy tissues, drastically improving patients’ survival and quality of life.

Furthermore, CNAO is expanding its capabilities as a premier multi-center utilizing new ion species, like Helium, later Oxygen and Neon. Soon, treatments will incorporate the Leo Cancer Care upright positioning and imaging system. The immediate future also includes beginning therapies with a Hitachi dedicated proton accelerator and gantry and a BNCT system for metastatic diseases, equipped with an electrostatic accelerator produced by TAE Life Science. With these new technologies, CNAO will become one of the most technologically advanced center in the world.

To date, over six thousand individuals, including approximately three hundred children and adolescents, have benefited from these life-saving treatments.

During his visit, the Pope engaged with CNAO’s Board of Directors, a collaborative body uniting national universities, clinical institutions, and research centers. He also extended his heartfelt greetings to the two hundred employees of the center. These doctors, physicists, engineers, and researchers tirelessly operate the advanced technologies in the service of oncology patients.

The emotional pinnacle of the day was the Holy Father’s private gathering with a delegation of young children who underwent treatment. The paediatric patients and their families shared a deeply touching moment of closeness, receiving the Pope’s comforting embrace.

“The visit of Pope Leo XIV honours us and represents a moment of extraordinary human value”, stated CNAO President Gianluca Vago. “In his encyclical Magnifica Humanitas, the Holy Father emphasizes the necessity of a science that constantly safeguards the centrality of the person and directs technology toward the common good. In a time marked by global tensions, CNAO testifies daily how the incredible power of the atom can be used not to destroy, but to heal. The particle beams we utilize against disease are, symbolically, Rays of Hope, sharing and supporting the IAEA project bearing this name. The embrace the Holy Father reserved for our children reminds us that scientific research finds its most authentic purpose when it encounters listening, compassion, and hope”.

Photo – https://mma.prnewswire.com/media/2997869/Papa_al_Cnao_crediti_Andrea_Perotti.jpg
Logo – https://mma.prnewswire.com/media/2997643/CNAO_Logo.jpg

 

 

View original content:https://www.prnewswire.co.uk/news-releases/pope-leo-xiv-embraces-paediatric-patients-at-cnao-in-pavia-302805799.html

Continue Reading

Trending