View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

🚨 ACTIVE EXPLOITATION

  • Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts — BleepingComputer
    Attackers hijack hotel Wi-Fi DNS to redirect users to fake Microsoft 365 login pages and steal credentials.
    • Targets users connecting to hotel and conference center Wi-Fi worldwide, including US, India, Saudi Arabia
    • Attackers modify DNS settings on compromised Wi-Fi gateways to redirect Microsoft 365 login traffic
    • Phishing domains used include m365-owa.com, owa-ms365.com, ms365-device.com, and ms365-live.com
    • Attack bypasses MFA by abusing device-code authentication flow to obtain OAuth tokens without stealing credentials
    • Some attacks attempt WPAD proxy abuse to route Windows app traffic through attacker-controlled proxies

🕵️ RESEARCH & DEEP DIVES

  • Microweber CMS 2.0.20 vulnerable to server-side template injection allowing OS command execution — CVE ThreatInt
    Microweber CMS 2.0.20 has a server-side template injection vulnerability enabling OS command execution.
    • Applies to Microweber CMS version 2.0.20 and earlier
    • Vulnerability is a server-side template injection via mail templates
    • Requires authenticated administrator privileges to exploit
    • Exploitation involves injecting malicious Twig expressions into unsanitized mail template bodies
    • Triggers automatic execution of arbitrary OS commands on mail dispatch events

🔓 CVEs & KEV

  • 19 other CVEs reported, worst scoring 8.8 on CVSS.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check