[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:russian-state-apt-linked-to-recent-public-wi-fi-gateway-hacking-msehticg":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":14,"article_ids":15,"ioc_summary":17,"source_urls":18,"status":20,"expires_at":21,"created_at":22,"updated_at":23,"articles":24},"1fc0c767-b3e7-48e0-882f-372acfae5922","Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking","russian-state-apt-linked-to-recent-public-wi-fi-gateway-hacking-msehticg","Russian state APT Storm-2945 is compromising public Wi-Fi gateways at hotels and conferences to steal Microsoft 365 credentials from traveling employees. Victims are redirected through DNS\u002FHTTP manipulation attacks and served malware disguised as browser updates. This is an active campaign targeting our mobile workforce with no known CVEs.","critical","advisory",[],[13],"Microsoft","Hunt for suspicious device code authentication attempts and browser update prompts on corporate endpoints that connected to public Wi-Fi in the last 30 days. Block known CornFlake and ChocoShell C2 domains and monitor for lateral movement from compromised M365 accounts.",[16],"e1d015da-e9f3-4462-a849-f0e5a0dc3383",null,[19],"https:\u002F\u002Fwww.securityweek.com\u002Frussian-state-apt-linked-to-recent-public-wi-fi-gateway-hacking\u002F","archived","2026-08-06T10:06:03.261+00:00","2026-08-04T10:06:12.316785+00:00","2026-08-06T10:06:31.474206+00:00",[25],{"id":16,"title":6,"url":19}]