[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2ao98ZAdgCPIU8PVIEMRBrlFjm5PUwrebkyR7vLaC28":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":29,"category":30,"article_tags":34},"2637ecfa-d40f-4326-a72c-937a26cbf6d3","Detect and disrupt AI-themed attacks with Microsoft Defender","detect-and-disrupt-ai-themed-attacks-with-microsoft-defender-fb02f3","See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain. The post Detect and disrupt AI-themed attacks with Microsoft Defender appeared first on Microsoft Security Blog.","A sub-cluster of the Russian threat actor Midnight Blizzard, known as Storm-2945, has been actively targeting hospitality organizations since May 2026. Operating under the campaign name CaptiveCrunch, the group compromises hotel sign-in portals to deliver malware and steal traveler credentials.","Midnight Blizzard sub-cluster Storm-2945 targets hospitality sign-in portals for malware and credential theft.","July 31 20 min read CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch.","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F09\u002F10\u002Fdetect-and-disrupt-ai-themed-attacks-with-microsoft-defender\u002F","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002Fwp-content\u002Fuploads\u002F2026\u002F09\u002FDetect-disrupt-ai-attacks.jpg","2026-09-10T16:00:00+00:00","2026-09-10T18:00:23.443158+00:00",8,[18,21,23,26],{"name":19,"type":20},"Midnight Blizzard","threat_actor",{"name":22,"type":20},"Storm-2945",{"name":24,"type":25},"CaptiveCrunch","campaign",{"name":27,"type":28},"Microsoft","vendor","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":29,"icon":31,"name":32,"slug":33},null,"Threat Intelligence","threat-intelligence",[35,40,45],{"category":36},{"id":37,"icon":31,"name":38,"slug":39},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":41},{"id":42,"icon":31,"name":43,"slug":44},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":46},{"id":47,"icon":31,"name":48,"slug":49},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",[51,55,58],{"type":52,"value":53,"context":54},"mitre_attack","T1566","Phishing",{"type":52,"value":56,"context":57},"T1078","Valid Accounts",{"type":52,"value":59,"context":60},"T1190","Exploit Public-Facing Application"]