Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cyber Threats Exploit Public Wi-Fi to Access Corporate Accounts

Cyber Threats Exploit Public Wi-Fi to Access Corporate Accounts

Posted on July 27, 2026 By CWS

Cybersecurity experts have uncovered a new wave of cyber attacks exploiting public Wi-Fi networks to infiltrate corporate accounts. According to a report by ReliaQuest, hackers have targeted organizations operating captive portal networks to access Microsoft 365 accounts of employees on business trips.

DNS Manipulation and Credential Theft

The attackers employed a sophisticated method by altering the DNS settings of compromised small office/home office (SOHO) routers. This manipulation redirects users to malicious infrastructure controlled by the attackers, enabling them to capture login credentials.

These cyber activities have been ongoing since at least June 2026 and bear resemblance to the earlier FrostArmada campaign linked to APT28, a group associated with Russia’s GRU. The adversary-in-the-middle (AitM) technique used here allows interception and harvesting of sensitive information from unsuspecting victims.

Targeting Shared Venues Globally

ReliaQuest notes that the attacks have primarily targeted Wi-Fi gateways at shared venues such as hotels and conference centers. These incidents have been reported across the United States, India, and Saudi Arabia. Organizations providing captive Wi-Fi services, including airports and universities, are warned of similar vulnerabilities.

Analysis indicates that these attacks are not confined to specific sectors. Industries ranging from financial and legal to healthcare and retail have been affected, highlighting the indiscriminate nature of the campaign aimed at business travelers worldwide.

Distinctive Tactics and Infrastructure

The recent attacks differ from the FrostArmada campaign in their use of DNS poisoning, suggesting a potential deviation in sophistication or caution compared to APT28. The infrastructure, including domain registrations and IP addresses, does not match previously known APT28 activities.

The focus on captive portal appliances in public venues marks a new approach that wasn’t documented in prior campaigns. This shift in tactics requires organizations to enhance their security measures to protect against evolving threats.

ReliaQuest’s findings emphasize the need for heightened awareness and robust security frameworks to safeguard against these pervasive cyber threats. As the landscape of cyber attacks continues to evolve, organizations must adapt swiftly to protect their sensitive information.

Security Week News Tags:APT28, captive portal, corporate security, credential theft, cyber attacks, Cybersecurity, DNS configuration, Hacking, Microsoft 365, network security, public Wi-Fi, ReliaQuest, SOHO routers, Threat Actors, travel security

Post navigation

Previous Post: Dysphoria Botnet Adopts Blockchain for Enhanced Security
Next Post: GitHub Implements Cooldown to Thwart Malicious Packages

Related Posts

Nissan Confirms Impact From Red Hat Data Breach Nissan Confirms Impact From Red Hat Data Breach Security Week News
Astelia Secures M to Enhance Cybersecurity Solutions Astelia Secures $35M to Enhance Cybersecurity Solutions Security Week News
GitHub Breach Affects 3,800 Repositories in Major Hack GitHub Breach Affects 3,800 Repositories in Major Hack Security Week News
Bugcrowd Acquires Application Security Firm Mayhem Bugcrowd Acquires Application Security Firm Mayhem Security Week News
Linux Kernel Vulnerability Exposes Systems to Attacks Linux Kernel Vulnerability Exposes Systems to Attacks Security Week News
Beyond the Black Box: Building Trust and Governance in the Age of AI Beyond the Black Box: Building Trust and Governance in the Age of AI Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic
  • China-Linked Hackers Exploit Sogou Flaw for Backdoor
  • Hackers Hide AI Threats in Plain English, Evade Security
  • Exploits Target JFrog Artifactory Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic
  • China-Linked Hackers Exploit Sogou Flaw for Backdoor
  • Hackers Hide AI Threats in Plain English, Evade Security
  • Exploits Target JFrog Artifactory Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark