2705 stories
·
0 followers

Hackers Hijack Hotel Wi-Fi Gateways to Steal Microsoft 365 Accounts Without Phishing

1 Share

Threat actors are compromising hotel and conference-center Wi‑Fi gateways to steal Microsoft 365 accounts from traveling employees without sending phishing emails or infecting endpoints.

The campaign uses DNS poisoning and, in some cases, Microsoft device-code flow abuse to redirect users to attacker-controlled infrastructure.

The activity has reportedly been active since at least June 2026. It affects shared Wi‑Fi environments in multiple U.S. cities, India, and Saudi Arabia.

Financial services, legal, healthcare, energy, retail, and professional-services organizations have all had devices connect through affected gateways, showing that the campaign targets travelers rather than a single industry.

Hotel Wi-Fi Hijacks Microsoft 365 Accounts

The targeted devices are captive-portal appliances that control guest access at hotels, conference centers, airports, coworking spaces, and similar venues.

Once attackers obtain administrative access, potentially through exposed management services and weak or reused credentials, they can alter DNS settings for every client on the network.

DNS converts domain names into IP addresses.

By poisoning DNS responses at the gateway, attackers can answer a request for a legitimate Microsoft sign-in domain with an attacker-controlled IP address, silently steering the victim toward a spoofed Microsoft 365 page.

DNS spoofing is specifically designed to redirect users to malicious sites under attacker control.

ReliaQuest-linked reporting identified domains including m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com in the operation.

The infrastructure was associated with IP addresses 31.57.243[.]154, 104.194.159[.]150, and DNS-poisoning response address 38.146.28[.]75.

DNS poisoning attack flow (Source: reliaquest)
DNS poisoning attack flow (Source: reliaquest)

This method is especially dangerous because no malicious email, attachment, or endpoint exploit is required. A single compromised gateway can expose every guest device that accepts its DHCP-provided network configuration.

The operation shares tradecraft with prior router-focused activity attributed to APT28, also tracked as Fancy Bear and Forest Blizzard.

The overlap includes compromised network devices, malicious DNS configuration changes, adversary-in-the-middle techniques, and Microsoft 365 credential or token theft; however, the reported activity lacks direct technical evidence required to attribute it to APT28.

Attackers also attempted Web Proxy Auto-Discovery Protocol abuse, or WPAD, against some Windows and macOS systems.

WPAD can automatically obtain proxy settings after a device joins a network; a hostile gateway can direct the device to a malicious proxy auto-configuration file and potentially route application traffic through attacker infrastructure, ReliaQuest said.

Indicators of Compromise

TypeIndicatorDescription
IP address38.146.28[.]75DNS poisoning response IP address
IP address31.57.243[.]154Hosts m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com
IP address104.194.159[.]150IP address of ms365-live[.]com

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

The post Hackers Hijack Hotel Wi-Fi Gateways to Steal Microsoft 365 Accounts Without Phishing appeared first on Cyber Security News.



Read the whole story
NerdsToGo
2 days ago
reply
Share this story
Delete

2.2 Million Vehicles Exposed to KARR Bluetooth Security Flaw

1 Comment and 2 Shares

KARR Security System

Millions of drivers with a dealer-installed KARR Security System are being urged to update their KARR alarm using an iPhone or Android device after researchers uncovered a Bluetooth vulnerability that could allow nearby attackers to unlock or immobilize affected vehicles.   The flaw impacts more than 2.2 million vehicles equipped with the aftermarket security system, but it does not affect factory-installed vehicle software, Apple CarPlay or Apple's iPhone platform. 

KARR Security System Vulnerability Affects Dealer-installed Hardware 

The KARR Security System is installed by dealerships to secure vehicles on their lots. In many cases, the hardware remains connected even after buyers decline the paid KARR alarm service. Because it is third-party equipment, automakers cannot deliver fixes through their standard software update process.  Researchers from the University of California, San Diego found that attackers within Bluetooth range could lock or unlock vehicles, disable alarms, activate horns, flash lights, or prevent parked vehicles from starting. However, they confirmed the flaw cannot remotely start a vehicle or control it while driving. 

iPhone App Update Fixes KARR Alarm Flaw 

Acrisure Protection Group, which sells the KARR Security System, released a firmware update on July 20 after researchers privately disclosed the issue in January 2025. Owners using the KARR Security app on an iPhone should receive an update notification. Others must download the app, connect it to the KARR alarm, then navigate to "Customer Service" and "Firmware Update." The patch was released before presentations scheduled for DEF CON on August 9 in Las Vegas and the USENIX Security Symposium on August 12 in Baltimore.

Hidden KARR Security System Complicates Updates 

Researchers estimate at least half of affected owners never requested the KARR Security System. Dealerships often left deactivated hardware installed, yet researchers found these units continued broadcasting Bluetooth signals while vehicles were running and for up to 10 minutes after being switched off. Owners can identify the system by checking for a KARR or "SWDS" sticker on the driver's window or a blinking button beneath the dashboard. Most affected vehicles were purchased from Honda, Toyota, Mazda, Ford and Jeep dealerships in Southern California between 2017 and July 21, although impacted vehicles were also identified elsewhere.

Shared Bluetooth Key Exposes KARR Alarm Devices

Researchers discovered a universal authentication key embedded in the official smartphone app while reverse engineering Bluetooth communications. Using a proof-of-concept Android app, they unlocked vehicles, disabled KARR alarm functions, and triggered horns and lights. Although the flaw alone cannot steal a vehicle, researchers said it could provide quiet access before a commercially available locksmith tool creates a working key. Acrisure described the attack as "highly complex" and said the real-world risk is low. Neither UC San Diego nor Wired found evidence of criminals exploiting the vulnerability.

Privacy Concerns and Recommended Action

Researchers also warned that Bluetooth signals from the KARR Security System could reveal vehicle locations. Using the WiGLE wireless database, they estimated at least 2.2 million Bluetooth-enabled systems had been deployed and detected 97 KARR-equipped vehicles during a 20-minute drive near the UC San Diego campus.  Drivers should confirm whether their vehicle contains a KARR Security System, install the latest firmware using the iPhone or Android app, and contact their dealership or KARR support if they cannot complete the update. 
Read the whole story
NerdsToGo
2 days ago
reply
Share this story
Delete
1 public comment
denismm
1 day ago
reply
This isn’t quite “Palantir” levels of ironic naming but it’s getting there.

Ransomware Attacks Targeting Universities on the Rise

1 Share
Comparitech’s analysis of incidents in the first half of 2026 finds that the emergence of The Gentlemen ransomware has resulted in surge in attacks against higher education
Read the whole story
NerdsToGo
2 days ago
reply
Share this story
Delete

Origin Energy Confirms Cyberattack Exposed Customers’ Personal and Financial Data

1 Share

Origin Energy has confirmed that a recent cyberattack led to unauthorized access and disclosure of customers’ personal and partial financial data, raising fresh concerns over the resilience of Australia’s critical infrastructure providers.

The incident, disclosed in a series of updates between 22 and 24 July 2026, affects an as-yet-unknown number of accounts across the country’s largest electricity and gas retailer.

On 22 July, Origin first notified customers and the market that it was investigating a “potential security incident” involving possible unauthorized access to some customer data, while initially asserting that credit card and bank details were not believed to be impacted.

Origin Energy Confirms Cyberattack

That position shifted a day later, when the company confirmed that a hacker had gained unauthorized access to customer records and that the incident had progressed from a suspected event to a confirmed data breach.

In its 23 July update, Origin acknowledged that exposed information includes names, residential addresses, dates of birth, contact phone numbers and account information for affected customers.

The company also confirmed that partial financial data was accessed, specifically the last four digits of some credit cards and the last three digits of some bank accounts linked to those customer profiles.

Although Origin has stressed that incomplete card and account numbers cannot be used on their own to perform transactions or directly access accounts, security experts note that this level of detail significantly increases the value of the dataset to cybercriminals.

When combined with core identity attributes such as name, address, and date of birth, partial financial identifiers can be weaponized in targeted phishing, account recovery fraud, and social-engineering attacks masquerading as legitimate Origin, bank, or government communications.

The attack has also raised questions over how the threat actor obtained access. Media reports indicate that a self-styled hacker claimed to have accessed up to two million customer records using an employee’s logon.

The incident appears to involve compromised credentials and misuse of legitimate access to extract data from internal systems, highlighting persistent identity and access management challenges in large enterprises.

Origin CEO Frank Calabria has publicly apologized, stating that customers “trust Origin with their information” and acknowledging the potential impact on those whose data has been exposed.

From a governance perspective, Origin has engaged the Australian Cyber Security Center, the Australian Federal Police and the Office of the Australian Information Commissioner, signaling that the breach is being treated as a significant cyber incident under Australia’s regulatory and critical infrastructure oversight frameworks.

Authorities and security advocates are urging customers to remain vigilant, monitor financial and energy accounts for suspicious activity, and treat unsolicited contact claiming to be from Origin with caution, particularly if it involves requests for credentials, one-time codes or payment details.

As investigations continue, the incident is likely to intensify pressure on critical infrastructure operators to harden identity controls, accelerate breach detection capabilities and improve transparency around cyber incidents that affect millions of citizens.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

The post Origin Energy Confirms Cyberattack Exposed Customers’ Personal and Financial Data appeared first on Cyber Security News.



Read the whole story
NerdsToGo
2 days ago
reply
Share this story
Delete

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)

1 Share

Attackers are exploiting a critical authentication bypass vulnerability (CVE-2026-16232) that affects Check Point Security Management and Multi-Domain Security Management, the management servers that push policy to Check Point security gateways (i.e., firewalls). “An unauthenticated attacker can obtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes to the security policy and security configuration,” the company said. The vulnerability is being exploited, they confirmed, and a “handful” … More

The post Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232) appeared first on Help Net Security.

Read the whole story
NerdsToGo
2 days ago
reply
Share this story
Delete

Oracle drops 1,449 security patches like it's the new normal

1 Share
It's a bad day to be an Oracle admin: Big Red has just released 1,449 security patches ready to be applied. The patches were released as part of the company's quarterly security fixes, and the record number may partly reflect Oracle's internal push to harness AI for vulnerability detection, which it announced in April. Oracle also manages a huge product portfolio, and the patches span numerous products, so the total shouldn't come as too much of a surprise. Instead, experts speaking to The Register unanimously agreed that any concerns over the number of patches should be reserved for the admins responsible for applying them, rather than for Oracle's code quality. "While a record 1,449 patches sounds alarming, it mostly reflects the massive scale of modern software ecosystems and the industry's shift toward aggressive, automated security scanning," said Dray Agha, senior manager of security operations at Huntress. "Frankly, the real story isn't the sheer volume of bugs, but rather the immense operational strain this puts on enterprise IT teams who must now race to separate the critical threats from the routine fixes without breaking business operations." Others, like Matei Badanoiu, lead security researcher at Pentest-Tools.com, say these bumper batches of security updates are likely to become the norm, owing mainly to AI-assisted bug hunting. Microsoft's monthly Patch Tuesday updates have ballooned in size in the last few months too, and not without warning. July's record 622 CVEs eclipsed June's 206, which at the time was an all-time high, and Microsoft warned just days before that the role of AI in vulnerability detection will make defenders even busier. "As AI helps defenders discover more issues, customers will see a higher volume of security updates included in each security release," Microsoft Windows veep Pavan Davuluri wrote in a blog post. Davuluri noted that Microsoft offers various automated patching tools and encouraged customers to make use of them to ease the ever-increasing burden of applying an unprecedented volume of security fixes. Similarly, Oracle's Integrated Cyber Center wrote in a blog post that customers feeling overwhelmed by the scale of their patching duties should make use of support resources provided by its various teams: My Oracle Support, Technical Account Management, and Customer Success. Big Red's big bet on AI for vulnerability detection has also led to a shakeup in how it delivers patches to customers. Starting in May 2026, Oracle began supplementing its quarterly updates with monthly patch batches for the most critical bugs it finds. Named Critical Security Patch Updates (CSPUs), these will be smaller but more frequent, allowing defenders to stay on top of the most pressing threats. Oracle said: "This approach enables customers to apply critical fixes more quickly on premises, while continuing to support established quarterly patching cycles through cumulative updates." Priority patches Only ten of the 1,449 patches carried a maximum CVSS score of 10.0, all of them affecting Oracle Fusion Middleware. Of these, two were highlighted as particularly dangerous by the Dutch NCSC: CVE-2026-47056 and CVE-2026-60217. Neither vulnerability is cataloged with a Common Weakness Enumeration (CWE) identifier, although both are described as easily exploitable. An unauthenticated attacker can exploit CVE-2026-47056 via HTTP to take over Oracle Data Integrator, while CVE-2026-60217 allows the same against Oracle Coherence over TCP. Urging customers to apply updates as soon as possible, NCSC-NL said: "Depending on the vulnerability, an attacker can execute malicious code, view sensitive data, or take over a system completely. Due to the severity of the vulnerabilities and the lack of authentication, the risk of exploitation is high." Badanoiu, meanwhile, told us that he was especially concerned about CVE-2026-61211 (9.9) and CVE-2026-47040 (9.1) – the two top-rated vulnerabilities affecting Oracle Database Server. "CVE-2026-47040, in Oracle Net Service, leads to an unauthenticated vulnerability through which attackers gain access to any stored data and the risk of persistently crashing the service," he explained. "And CVE-2026-61211, in the DBMS_CLOUD package, carries the highest score in the batch, where a low-privilege attacker can get remote code execution and takeover of Oracle's RDBMS as well as downstream implications for other products that use the database." ®

Read the whole story
NerdsToGo
2 days ago
reply
Share this story
Delete
Next Page of Stories