Threats · 58 days ago
A hijacked captive portal can do more than annoy travelers. It can steer their device to attacker-chosen update pages or a real Microsoft sign-in flow, which turns hotel Wi‑Fi into a path to surveillance malware or an MFA-satisfied session.
Microsoft says the campaign has run since early May across hospitality networks in several countries. On compromised gateways, the portal also served as DNS, letting attackers forge answers, redirect update checks, and since July 16 push some victims into Microsoft's device-code flow; CornFlake then captured webcam, microphone, keystrokes, cookies, and cloud tokens.
The risk is broader than one infected laptop. A traveler's corporate identity can be handed over through a legitimate login page, and the session can survive the usual password-reset style response.
1 source covering this story
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
Microsoft links hijacked hotel Wi-Fi to fake updates that deliver CornFlake, steal cloud tokens, and abuse device codes to target travelers.
Part of the PlainSec briefing for 2026-08-02