LIVE · cybersecurity feed
Live wire
CVE-2026-66066 · KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)Rails patches critical Active Storage flaw with RCE potentialCVE-2026-48449 · Adobe fixed a maximum-severity vulnerability flaw in Campaign ClassicRuby on Rails Patches Critical VulnerabilityHackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer SitesHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance MalwareCaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theftHollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law FirmCVE-2026-33017 · Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability ExploitsThis month in security with Tony Anscombe – July 2026 edition
breach

Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. [...]

zeroday.news · 5h ago

Microsoft has confirmed a global campaign targeting hospitality Wi-Fi networks, which it attributes to the Russian state-sponsored threat actor Midnight Blizzard, also known as APT29. The campaign, dubbed "CaptiveCrunch" by Microsoft, has been active since at least early May, though the threat actor has engaged in device and OAuth code phishing operations since February.

The attackers manipulate DNS and HTTP traffic on networks served by captive portal equipment, allowing them to intercept user connections to hotel and conference center Wi-Fi. While the exact initial compromise method remains undetermined, Microsoft noted signs of breaches in shared infrastructure rather than isolated devices. After modifying DNS settings, victims are redirected to phishing pages impersonating Microsoft 365 login portals or to device code phishing pages that exploit Microsoft Entra ID authentication flows. This activity has been observed since July.

A newly disclosed tactic involves using fake browser and operating system update pages that deliver malware to Windows via "ClickFix" prompts for user verification. Evidence also suggests that Android devices are being targeted to deliver APK files through similar ClickFix landings.

Microsoft identified two new malware families, CornFlake and ChocoShell, used in the campaign. CornFlake is a Go-based remote access trojan (RAT) with capabilities including remote shell access, keylogging, clipboard monitoring, screenshot capturing, microphone and webcam surveillance, browser credential and cookie theft, Microsoft 365 session token theft, file exfiltration, USB monitoring, and system reconnaissance. When executed, CornFlake displays a fake progress window, which can appear as a Windows update, Defender virus scan, disk optimization utility, network diagnostics tool, browser update prompt, or document viewer installer, while it copies itself to %AppData% for persistence. It disguises itself as "Cloud Sync Service" and uses multiple persistence mechanisms, including Windows service registrations, registry run keys, named tasks, and a watchdog routine.

The second payload, ChocoShell, is an in-memory PowerShell credential stealer. It targets browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials. Based on extensive code comments, Microsoft assesses that AI tools were likely used in the development of both malware families.

Researchers also discovered an unprotected web-based management panel named "FruitStone" used by the threat actor to manage infected systems. This panel allowed them to browse victim files, execute PowerShell commands, and capture screenshots and keystrokes.

Microsoft recommends treating hotel and conference Wi-Fi as untrusted networks, advising users to utilize private cellular or managed connections whenever possible. Users should avoid installing software updates or tools offered through captive portals. The company also suggests adopting phishing-resistant authentication methods like MFA and passkeys, disabling Microsoft Entra device code authentication when not needed, and refraining from using corporate credentials to register for guest Wi-Fi networks.

breachmalwarenation-statehealthcare
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Anthropic: AI Attacks Result of Security Gaps, Not Model Issues

Last month's incidents in which Claude breached real-world systems derived from over-permissioning, especially with Internet access.

security

New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems

The grants will help local governments assess and improve cyber defenses amid a multistate campaign targeting water and wastewater infrastructure. The post New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems appeared first on SecurityWeek.

ai

Public interest coalition urges Congress to investigate OpenAI, Hugging Face hack

The post Public interest coalition urges Congress to investigate OpenAI, Hugging Face hack appeared first on CyberScoop.

security

“Adult TikTok” searches lead to scams

That "free" adult TikTok site could leave you with spam, unwanted apps, or fake verification fees.

ai

The AI Act kicks into action, forces companies to be clear about AI chatbots

The European Union (EU) has started enforcing key parts of the AI Act, with immediate, visible consequences for chatbots, deepfakes and other consumer‑facing AI.

security

Californians can tell data brokers to DROP their information

California has launched the Delete Request and Opt‑out Platform (DROP), a state‑run portal that lets residents send deletion and opt‑out requests to all registered data brokers.