Threat actor bypasses detection, protections in Microsoft Azure Serial Console

A threat actor Mandiant calls UNC3944 was observed abusing privileged accounts to access the Microsoft Azure Serial Console. In doing so, UNC3944 bypassed many of the defense and detection methods used within Azure, thereby gaining full administrative access to the text-based console for Windows virtual machines (VMs).

Read full article on SC Magazine

 


Date:

Categorie(s):