Tag

Captive Portal

All articles tagged with #captive portal

Russian‑linked group targets hotel Wi‑Fi to steal Microsoft 365 tokens
technology23 days ago

Russian‑linked group targets hotel Wi‑Fi to steal Microsoft 365 tokens

Microsoft ties a global hospitality Wi‑Fi campaign to the Russian group Midnight Blizzard (Storm-2945), detailing DNS tampering and two malware families, CornFlake and ChocoShell, used to steal Microsoft 365 tokens and credentials via phishing, device-code prompts, and fake update pages; researchers urge treating hotel Wi‑Fi as untrusted, using MFA/passkeys, and avoiding corporate credentials on guest networks.

PAN-OS Captive Portal zero-day enables remote code execution on exposed firewalls
technology3 months ago

PAN-OS Captive Portal zero-day enables remote code execution on exposed firewalls

Palo Alto Networks warned of a critical, unpatched vulnerability in the PAN-OS User-ID Authentication Portal (Captive Portal), CVE-2026-0300, that can be triggered by crafted packets to allow unauthenticated remote code execution with root privileges on internet-exposed PA-Series and VM-Series firewalls; exploitation has been observed as limited but ongoing, with Shadowserver counting thousands of exposed VM-series endpoints. Until a patch is released (updates expected May 13, 2026), admins are advised to restrict portal access to trusted networks or disable it, noting the issue does not affect Cloud NGFW or Panorama.