Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

7 / 7 results
Active filter:tag: #hospitality✕ clear
Attackers abuse legitimate Node.js runtime to evade detection in attackshighbug_reportVulnerability
bug_reportVulnerability

Attackers abuse legitimate Node.js runtime to evade detection in attacks

Organizations using Node.js in their environments, particularly government departments, technology companies, hotels, fintech, e-commerce, professional services, and retail logistics.

Node.js3 Sep · 08:43 UTC
Midnight Blizzard targets hospitality Wi-Fi in CaptiveCrunch campaignhighperson_alertThreat Actor
person_alertThreat Actor

Midnight Blizzard targets hospitality Wi-Fi in CaptiveCrunch campaign

Midnight Blizzard (APT29, also tracked as Storm-2945, IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo) is a Russian-attributed advanced persistent threat group linked to intelligence collection operations.

Microsoft3 Aug · 22:17 UTC
Storm-2945 Hijacks Hotel Wi-Fi to Deploy CornFlake Surveillance RAThighperson_alertThreat Actor
person_alertThreat Actor

Storm-2945 Hijacks Hotel Wi-Fi to Deploy CornFlake Surveillance RAT

Storm-2945 is assessed by Microsoft to be an operational sub-cluster of Midnight Blizzard (APT29, Cozy Bear), which the U.S. and U.K. governments attribute to Russia's Foreign Intelligence Service (SVR). The U.K.

Microsoft1 Aug · 04:29 UTC
Storm-2945 Exploits Captive Portals in CaptiveCrunch Espionage Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Storm-2945 Exploits Captive Portals in CaptiveCrunch Espionage Campaign

Storm-2945 is an operational sub-cluster of Midnight Blizzard (APT29), a Russia-based threat actor attributed by US and UK governments to the Foreign Intelligence Service of the Russian Federation (SVR).

Microsoft Security31 Jul · 19:01 UTC
DNS hijacking on hotel Wi-Fi redirects users to fake Microsoft 365 loginshighbug_reportVulnerability
bug_reportVulnerability

DNS hijacking on hotel Wi-Fi redirects users to fake Microsoft 365 logins

Wi-Fi gateways at hotels and conference centers in multiple U.S. cities, India, and Saudi Arabia. Targets traveling employees from financial services, professional services, legal, healthcare, energy, and retail sectors accessing Microsoft 365.

Microsoft24 Jul · 15:50 UTC
Phishing campaign targets hotel front desks with Node.js implanthighbug_reportVulnerability
bug_reportVulnerability

Phishing campaign targets hotel front desks with Node.js implant

Hotel and hospitality organizations in Europe and Asia. Front-desk systems targeted via photo-themed ZIP file attachments containing Node.js-based malware. Campaign active since April 2026.

Microsoft26 Jun · 07:27 UTC
Active campaign targets hospitality in Europe/Asia via ZIP archiveshighbug_reportVulnerability
bug_reportVulnerability

Active campaign targets hospitality in Europe/Asia via ZIP archives

Hospitality organizations in Europe and Asia. Attack vector: photo-themed ZIP archives containing malicious shortcut files that deploy a Node.js implant.

Microsoft25 Jun · 20:30 UTC