Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

2026-08-01T14:51:41Z29d03faaa95df38ed8627061809113005f411fb4556a24c321f0453f2e31af08
CVE-2026-48449AI securityAPT29Adobe Campaign ClassicAndroid RATCaptiveCrunchClickFixCozy BearDLL sideloadingDNS hijackingFlying EagleLLM-assisted vulnerability discoveryMicrosoft 365 token theftMidnight BlizzardRussian state-sponsored activitySilverFoxSouth KoreaStorm-2945ValleyRATauthorization flawbrand impersonationcredential thefthotel Wi-Fikernel driversremote code executionwatering-hole attacks

What happened

Security news covering Russian SVR-linked Storm-2945/ Midnight Blizzard abuse of hotel Wi-Fi portals to distribute malware and steal Microsoft 365 tokens; a critical Adobe Campaign Classic remote code execution vulnerability (CVE-2026-48449, CVSS 10.0); South Korean watering-hole attacks; advanced SilverFox ValleyRAT activity; Android RAT infrastructure; brand-impersonation and ClickFix campaigns; and the expanding use of AI in vulnerability discovery, security evaluations, and offensive operations.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
29d03faaa95df38ed8627061809113005f411fb4556a24c321f0453f2e31af08
Enrichment time
2026-08-01T14:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.