Elektrine lite

← Feed

@dannyjpalmer@infosec.exchange

Post #4063405

2026-07-24 13:01 UTC

A widespread DNS poisoning campaign is targeting the hotels, conference venues and the hospitality sector with credential harvesting attacks designed to steal corporate login credentials from visitors, researchers have warned. Identified by cybersecurity analysts at ReliaQuest, the campaign begins by targeting routers used to provide public Wi-Fi to visitors to hotels, conference centers and other shared venues frequently visited by corporate employees. These compromised Wi-Fi gateways were identified around the world, including across multiple US cities, India and Saudi Arabia. (Researchers point out that the tactics look suspiciously similar to APT28/Fancy Bear... 👀 ) https://www.infosecurity-magazine.com/news/hotel-wifi-dns-poisoning/ #cybersecurity

Replies (2)

  • @dannyjpalmer@infosec.exchange Love your articles.

    Open ##4235740

  • @dannyjpalmer@infosec.exchange I've often criticized the very large defense contractor I work for because 1) our laptops have to connect to an untrusted network _first_ , then onto the VPN, if the user cares. Then 2) with the VPN on, they don't confine _all_ traffic inside. Yep, DNS runs outside the VPN. My personal laptop, OTOH, connects to a travel router, which in turn connects to the hotel. So NAT plus the host firewall. And DoT for DNS, plus DNSSEC.

    Open ##4235747