Connect with us

Technology

Guardz Uncovers Sophisticated Campaign Exploiting Legacy Authentication in Microsoft Entra ID

Published

on

The Guardz Research Unit uncovered a coordinated cyber campaign using outdated login methods to bypass MFA and infiltrate cloud environments by attempting to exploit basic authentication protocols 

MIAMI, May 7, 2025 /PRNewswire/ — Guardz, the cybersecurity company empowering Managed Service Providers (MSPs) and IT professionals to protect small businesses with AI-native unified detection and response, today disclosed its discovery of an advanced attack campaign exploiting legacy authentication protocols in Microsoft Entra ID. Uncovered by the Guardz Research Unit (GRU), the campaign was active between March 18 and April 7, 2025, and shows how outdated authentication methods, particularly BAV2ROPC, continue to be exploited by threat actors to bypass modern identity protection systems, including Multi-Factor Authentication (MFA) and Conditional Access Policies.

The campaign has since subsided, but Guardz warns that vulnerability continues to exist in many environments, posing a critical risk to organizations that have not yet fully modernized their authentication frameworks. Sectors that were identified as being disproportionately targeted by this vulnerability include financial services, healthcare, manufacturing, and technology services.

“This campaign is a wake-up call—not just about one vulnerability, but about the broader need to retire outdated technologies that no longer serve today’s threat landscape,” said Dor Eisner, CEO and Co-Founder of Guardz. “At Guardz, we’re focused on helping small businesses and the MSPs that serve them stay ahead of evolving attacks by identifying hidden risks before they’re exploited.”

Guardz detected over 9,000 suspicious login attempts from distributed IP addresses, primarily originating in Eastern Europe and the Asia-Pacific region, indicating a globally orchestrated effort. Attackers leveraged automation, IP rotation, and advanced tooling to probe security controls and gain unauthorized access to cloud resources, particularly Exchange Online.

The attack unfolded in two major phases:

Initialization (March 18-20): Low-intensity probing with approximately 2,709 attempts per day.Sustained Attack (March 21-April 3): Spiking to over 6,444 attempts per day – a 138% increase – marking a move to aggressive exploitation.

Guardz tracked this progression using new AI-driven research methods and internal systems designed to continuously hunt for anomalous behavior and active threat campaigns on the dark web. The company’s AI agents executed thousands of actions in tandem with human GRU researchers, identifying patterns across IPs, geographies, and attack tools.

The campaign zeroed in on Basic Authentication Version 2 – Resource Owner Password Credential (BAV2ROPC), a behind-the-scenes compatibility mechanism in Entra ID that allows legacy applications to authenticate using usernames and passwords. Unlike modern, interactive login flows that enforce MFA and security checks, BAV2ROPC operates non-interactively and bypasses MFA, Conditional Access Policies, and login alerts and user presence verification.

Guardz urges all organizations to immediately mitigate risks from legacy authentication by auditing and disabling outdated protocols, enforcing modern authentication and MFA across all accounts, implementing conditional access policies to block unsupported flows like ROPC, and closely monitoring for unusual login activity or failed authentication patterns.

Recognizing that small businesses often lack the in-house teams and infrastructure available to larger enterprises, Guardz bridges this gap with its AI-powered cybersecurity platform that delivers identity protection, email security, threat detection, and automated incident response, purpose-built for the needs of small organizations.

To explore Guardz’s findings on the legacy authentication attack campaign and how its platform defends against such threats, read the full research blog here.

About Guardz

Guardz provides MSPs and IT professionals with an AI-powered cybersecurity platform designed to secure and insure SMBs against cyberattacks. The Guardz platform offers automatic detection and response, protecting users, emails, devices, cloud directories, and data. By simplifying cybersecurity management, Guardz enables businesses to focus on growth without being bogged down by security complexities. The company’s scalable and cost-effective pricing model ensures comprehensive protection for all digital assets, facilitating rapid deployment and business expansion.

Media Contact
Allison Grey
allison@headline.media
+1 323 283 8176

 

View original content:https://www.prnewswire.com/news-releases/guardz-uncovers-sophisticated-campaign-exploiting-legacy-authentication-in-microsoft-entra-id-302448704.html

SOURCE Guardz

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

Accord Specialty Pharmacy Named Finalist in MMIT’s 11th Annual Retail Specialty Pharmacy Patient Choice Awards

Published

on

By

ORLANDO, Fla., April 23, 2026 /PRNewswire/ — Accord Specialty Pharmacy, an independent specialty pharmacy serving patients across multiple states, has been named a finalist in the MMIT Patient Choice Awards, a recognition based on patient-reported satisfaction and experience.

Accord was selected as the only independent pharmacy among finalists in its category, alongside national pharmacy organizations such as Walgreens Specialty Pharmacy and Walmart Specialty Pharmacy. This distinction highlights the company’s commitment to delivering personalized, high-touch care for patients managing complex and chronic conditions.

The MMIT Patient Choice Awards recognize specialty pharmacies that demonstrate excellence in patient satisfaction, service quality, and overall care experience. Finalists are determined based on direct patient feedback, making the recognition a meaningful reflection of the trust patients place in their pharmacy providers.

“Being recognized alongside national organizations and as the only independent finalist validates our belief that personalized, patient-centered care drives better outcomes. We are building a model that combines clinical depth, national reach, and operational flexibility to better serve patients, providers, and partners.” said AJ Patel, Founder and Pharmacy Manager of Accord Specialty Pharmacy.

Accord Specialty Pharmacy supports patients across complex specialty categories, including oncology, rare disease, and infusion, through a clinically driven, high-touch care model designed to improve access, adherence, and outcomes. The company’s approach emphasizes personalized support, responsive care coordination, and strong clinical engagement to help patients navigate complex therapies more effectively. With a growing national footprint and multi-state licensure, Accord is positioned to support patients, providers, and partners across diverse markets.

For more information, visit MMIT Announces Finalists of the 11th Specialty Pharmacy Patient Choice Awards – MMITNetwork.

About Accord Specialty Pharmacy:

Accord Specialty Pharmacy is an ACHC-accredited, multi-state licensed independent specialty pharmacy located in Central Florida, dedicated to delivering high-quality, patient-centered care for individuals managing complex and chronic conditions. Through personalized support, clinical expertise, and a high-touch approach, Accord helps patients navigate every step of their treatment journey. Learn more at www.accordspecialty.com.

CONTACT: contact@accordspecialty.com

View original content to download multimedia:https://www.prnewswire.com/news-releases/accord-specialty-pharmacy-named-finalist-in-mmits-11th-annual-retail-specialty-pharmacy-patient-choice-awards-302752327.html

SOURCE Accord Specialty

Continue Reading

Technology

HAIVISION ANNOUNCES VOTING RESULTS FROM 2026 ANNUAL MEETING OF SHAREHOLDERS

Published

on

By

MONTRÉAL, April 23, 2026 /CNW/ – Haivision Systems Inc. (“Haivision” or the “Company”) (TSX: HAI) is pleased to announce the voting results from its annual meeting of shareholders held today in a virtual format.

A total of approximately 45.97 % of the issued and outstanding common shares of Haivision were represented at the meeting.

Election of Directors

Each of the six nominated directors of Haivision was elected as director of the Company with the following results:

Director

Votes
For

% Votes
For

Votes
Against

% Votes
Against

Miroslav Wicha

11,110,245

99.26 %

82,583

0.74 %

Harvey Bienenstock

11,155,137

99.66 %

37,691

0.34 %

Robin M. Rush

11,121,855

99.37 %

70,973

0.63 %

Neil Hindle

10,794,005

96.44 %

398,823

3.56 %

Julie Tremblay

10,941,969

97.76 %

250,859

2.24 %

Lee K. Levy II

9,084,418

81.16 %

2,108,410

18.84 %

2.   Appointment of Auditors

Deloitte LLP were reappointed auditors of the Company for the ensuing year with 12,492,582 (98.84%) votes cast in favour and 146,406 (1.16%) votes withheld.

3.   Approval of the Unallocated Awards under the Company’s Equity Incentive Plan

The Company’s unallocated awards were approved with 8,710,347 (77.82%) votes cast in favour and 2,482,481 (22.18%) votes cast against.

4.   Reapproval of Company’s Shareholder Rights Plan

The Company’s shareholder rights plan was approved with 10,572,490 (94.46%) votes cast in favour and 620,338 (5.54%) votes cast against.

Final voting results on all matters voted on at the meeting will be filed under Haivision’s profile on SEDAR+ at www.sedarplus.ca.

About Haivision

Haivision is a leading global provider of mission-critical, real-time video streaming and visual collaboration solutions. Our connected cloud and intelligent edge technologies enable organizations globally to engage audiences, enhance collaboration, and support decision making. We provide high quality, low latency, secure, and reliable live video at a global scale. Haivision open sourced its award-winning SRT low latency video streaming protocol and founded the SRT Alliance to support its adoption. Awarded four Emmys® for Technology and Engineering from the National Academy of Television Arts and Sciences, Haivision continues to fuel the future of IP video transformation. Founded in 2004, Haivision is headquartered in Montreal and Chicago with offices, sales, and support located throughout the Americas, Europe, and Asia. Learn more at haivision.com.

View original content to download multimedia:https://www.prnewswire.com/news-releases/haivision-announces-voting-results-from-2026-annual-meeting-of-shareholders-302752318.html

SOURCE Haivision Systems Inc.

Continue Reading

Technology

Noritz upgrades EZ Pro Series of tankless water heaters with larger, multi-function panel display for faster installation and servicing

Published

on

By

Improved, fully integrated diagnostic interface eliminates the need for a separate remote controller, providing key system status data and enhanced digital controls to ease startup, operation, and maintenance for pro installers and service techs.

FOUNTAIN VALLEY, Calif., April 23, 2026 /PRNewswire/ — Noritz America, an international leader in tankless and electric heat pump water heaters and high-efficiency combination boilers, has further enhanced its EZ Series Pro line of residential condensing tankless water heaters by expanding both the size and the functionality of the units’ built-in control panel, whose user-friendly digital interface is mounted prominently on the front exterior.

Providing upgraded monitoring and diagnostic capabilities, the multi-function panel display allows professional installers to view system status, temperature settings, service reminders, maintenance data, error codes, error history, and (if applicable) recirculation timing settings. All of this vital information is built in and readily accessible on the water heater. Besides eliminating the need for a separate, external remote controller, the panel enables guided setup during installation and faster, more effective troubleshooting.

In addition, installers and users can monitor and program the unit remotely via Bluetooth® connectivity that works alongside the panel, using the EZ Start Plus app on their smartphones. A separate external remote is optional.

“The intent of our upgrade efforts was to create a more satisfying user experience for both the professional and the consumer,” says Noritz Executive Vice President and General Manager Jason Fleming. “We focused on simplified installation, advanced diagnostics, and giving professionals and their customers easier, more responsive control of the water heater.”

Essential Features of the Multi-Function Panel

Below are the main features and capabilities of the upgraded, built-in, multi-function panel and related control system:

Digital temperature control: Professional installers and service technicians will find it easier to use the enlarged panel to set the output water temperature to 100° – 140° Fahrenheit. Temperature settings are available in increments as small as 5°F.

Key benefits: More precise temperature control for professionals and, as a result, safer, more consistent hot-water delivery for end users.

Integrated Bluetooth connectivity; no more dip switches: The EZ Start Plus app enables installers and service techs to perform system setup, adjust the temperature, run diagnostics and share this information electronically with Noritz Technical Support. Installers can even register the water heater to qualify for the accompanying warranty.

Key benefits: Simplified startups mean faster installs, minimizing the manual programming that installers previously had to perform. Smartphone-based control and troubleshooting eliminate the need for old-style manual adjustment of physical dip switches.

Improved service access: Even the physical design of the EZ Series Pro has been reengineered to work more effectively with the newly enhanced multi-function panel.

Key benefits: The latched, snap-lock front cover enables quicker access to components for easier maintenance and servicing.

Industry-Best Warranty

The upgraded EZ Series Pro continues to include three models, all with a Uniform Energy Factor of 0.98, the highest efficiency rating in the tankless water heater industry:

EZ71: input range — 12,800 to 160,000 BTU/hour; flow rate — 0.4 to 9.0 gallons per minute; turndown ratio — 12.5:1EZ98: 12,800 to 180,000 BTUh; 0.4 to 9.8 gpm; 14:1;EZ111: 12,800 to 199,900 BTUh; 0.4 to 11.1 gpm; 16:1.

All three units carry a 25-year limited warranty on their stainless steel heat exchangers, the longest such protection in the industry. Further protection includes a five-year limited parts warranty and one year for reasonable labor.

The water heaters use natural gas but are field-convertible to LP with a parts kit included with every unit. Two water heaters can be linked using Noritz’s optional Quick Connect linkage to double the hot-water flow rate.

Designed for wall-mounting indoors, the EZ Series Pro heaters can be direct-vented with two-, three-, or four-inch Schedule 40 or Schedule 80 PVC or CPVC, or two-inch or three-inch polypropylene venting. They can also be installed outdoors in milder year-round climates using an optional vent cap.

All EZ Series Pro models have received approvals from CSA, NSF5, NSF372, and are Low NOx approved by the South Coast Air Quality Management District (Rule 1146.2).

For more information on the newly upgraded Noritz EZ Series Pro, visit: https://ezseries.noritz.com/

A short product video is available at: https://youtu.be/m5iDn7sOGMc

For more information on the full line of Noritz tankless water heating products, visit www.noritz.com. You can also contact us by telephone at 866.766.7489 or by email at support@noritz.com.

For editorial assistance, contact John O’Reilly or Emma Wurzer at GreenHouse Digital PR, 15255 South 94th Avenue, Suite 500 | Orland Park, IL 60462; tel.: 708.428.6385; e-mail: john@greenhousedigitalpr.com | emma@greenhousedigitalpr.com.

Hi-res versions of photographs to accompany this press release are available for immediate download by using this link: https://noritz.greenhousedigitalpr.com/ez-series-pro-upgrades.

NORITZ AMERICA CORPORATION, a subsidiary of Noritz Japan, has corporate offices in Fountain Valley, Calif., and Atlanta, offering a full line of tankless water heaters and high-efficiency combination boilers to meet the hot water demands of residential and commercial applications. Noritz supports its products with a national network of skilled representatives and employees committed to providing our communities with the finest products and services by helping consumers live a more comfortable, efficient, and healthy lifestyle. For more information on Noritz America and the entire line of Noritz’s ENERGY STAR® tankless water heaters, please call (877) 986-6748 or visit our website at www.noritz.com.

CONTACT:
Andrew Tran
Noritz America
(714) 433-7813
atran@noritz.com

View original content:https://www.prnewswire.com/news-releases/noritz-upgrades-ez-pro-series-of-tankless-water-heaters-with-larger-multi-function-panel-display-for-faster-installation-and-servicing-302752319.html

SOURCE Noritz

Continue Reading

Trending