Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

A recent report indicates that criminals are actively compromising public Wi-Fi devices globally, including those found in hotels and conference centers, to manipulate their Domain Name System (DNS) configurations. The objective of these attacks is to redirect unsuspecting users to malicious, spoofed login pages, thereby facilitating the theft of their credentials.
The core mechanism of this attack involves unauthorized access to the administrative interfaces of public Wi-Fi access points or routers. Once compromised, the attackers alter the DNS server settings on these devices. Normally, when a user attempts to access a website, their device queries a DNS server to translate the human-readable domain name (e.g., example.com) into an IP address. By changing the DNS settings on the Wi-Fi device, attackers can force all connected users to query a malicious DNS server under their control.
This malicious DNS server is then configured to provide incorrect IP addresses for popular websites, particularly those requiring user authentication. For instance, if a user attempts to visit a legitimate banking website, the compromised DNS server might resolve that domain name to the IP address of a fake login page hosted by the attackers. These fake pages are often meticulously crafted to mimic the appearance of legitimate sites, making them difficult for an average user to distinguish.
The scope of this threat is potentially broad, given the widespread availability and frequent use of public Wi-Fi networks in various hospitality and event venues. Users connecting to these networks, often without robust security measures on their own devices or a high degree of vigilance, are susceptible. The primary target appears to be credentials for a range of online services, including banking, email, social media, and other platforms that require login.
Mitigation for this class of attack typically involves several layers of defense. For network administrators of public Wi-Fi, securing access points with strong, unique passwords, regularly updating firmware, and implementing network segmentation are crucial. Disabling unnecessary administrative access from the wireless interface and monitoring DNS queries for anomalies can also help. For end-users, exercising caution when connecting to public Wi-Fi, using a Virtual Private Network (VPN) to encrypt traffic, and verifying website certificates (looking for HTTPS and a valid padlock icon) are recommended. Multi-factor authentication (MFA) on online accounts can also significantly reduce the impact of stolen credentials, even if they are compromised.
This incident highlights the persistent threat posed by compromised network infrastructure and the evolving tactics employed by cybercriminals to exploit user trust and convenience. It underscores the critical need for both network operators to maintain robust security postures and for individual users to adopt proactive security habits, especially when operating in environments with shared or untrusted network access.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed