July 26, 2026
- Compromised hotel Wi-Fi gateways are being used to DNS-poison travelers onto fake Microsoft 365 login pages and steal MFA-satisfied OAuth tokens, active since June 2026, per CyberInsider. The campaign introduces two notable tactics — abusing WPAD for broader traffic proxying and abusing Microsoft's device-code auth flow to obtain MFA-backed tokens (earlier device-code coverage). @blackorbird notes the tradecraft is similar to APT28. · Cloud & Identity
in Hotel Wi-Fi Becomes an MFA-Bypass Machine for M365 Accounts