Midnight Blizzard Targets Travelers via Captive Portals

2026-08-03T14:52:07Za78be7029a5855d4b5cfc951de447a7f5ed9cb6f036276407edf73ab5ab1d40b
AI securityAI-enabled attacksAiTMDNS poisoningDNS tunnelingEDR evasionIranian threat actorsMidnight BlizzardNorth KoreaStorm-2945TA488TrickBotcaptive portal attackscloud securitycredential theftcryptominingcyber threat intelligenceidentity security security?äinfostealermalwarenpmphishingransomwarestate-sponsored activitysupply-chain attacks

What happened

A July–August 2026 cybersecurity news digest covering state-sponsored activity, phishing and credential theft, ransomware, malware and loaders, supply-chain compromise, AI-enabled attacks, cloud and identity risks, industrial-system targeting, and newly disclosed vulnerabilities. Notable items include captive-portal and hotel Wi-Fi attacks, npm supply-chain activity attributed to North Korea, Linux and Ubuntu privilege-escalation flaws, vulnerable Hugging Face model loading, Zimbra zero-click exploitation, and attacks against Siemens and Schneider industrial equipment.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
a78be7029a5855d4b5cfc951de447a7f5ed9cb6f036276407edf73ab5ab1d40b
Enrichment time
2026-08-03T14:52:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.