North Korean state-sponsored cyber actor, TA406, is carrying out phishing attacks and credential-stealing operations against Ukrainian government entities to gather intelligence on the Russian invasion, according to Proofpoint. The group’s tactics involve deploying emails impersonating staff from non-existent organizations and directing recipients to download malicious files. Some of the data collected includes system information and antivirus software details.

Researchers Detailed New Threat-Hunting Techniques to Detect Azure Managed Identity Abuse
Cybersecurity experts have developed advanced techniques to detect potential abuse of Azure Managed Identities (MIs), which streamline credential management but create new vulnerabilities. A research