Russian threat actor Midnight Blizzard is conducting widespread traffic manipulation attacks at hotels worldwide. Result: delivering malware or redirecting auth flows at their discretion, globally.
Since early May 2026, we saw this subcluster manipulate DNS and HTTP traffic from networks served by captive portals to redirect user traffic through actor-controlled infrastructure. We’re calling the campaign CaptiveCrunch.
“We have observed notable commonalities in the equipment and management systems used across multiple affected networks.”
We break down the malware & techniques, but the most important part is how dynamic all of it is: Midnight Blizzard is using AI to support a significant portion of these operations. They are moving and changing quickly.
Feedback welcome on the suggested mitigations: https://t.co/cVGbdQEpXQ
Help spread the word to VIPs in governments, diplomatic entities, non-governmental organizations (NGOs) in the US and Europe (probably also those traveling to Black Hat)
I finally gave all of my tools a home.
Introducing https://t.co/Rn1PNvksdV a central place to find the open-source PowerShell modules, scripts, and GUI utilities I’ve built for Microsoft Intune, Entra ID, Microsoft Graph, Windows Autopilot, and more.
These tools started the same way: I ran into a problem at work, built something to solve it, cleaned it up, and shared it so the next person wouldn’t have to build it twice.
You’ll find tools for:
🔹 Entra PIM role activation
🔹 Intune Multi Admin Approval
🔹 Windows LAPS
🔹 On-demand Intune Remediations
🔹 Autopilot device cleanup and registration
🔹 Entra access packages
Everything is open source, and I’ll continue adding new projects as I build them.
Take a look: https://t.co/h8ebXmgllo
If something helps you, let me know. Issues, feedback, and pull requests are always welcome!
#MicrosoftIntune #EntraID #MicrosoftGraph #PowerShell #WindowsAutopilot #OpenSource #MVPBuzz
If you want to learn Kerberos and all the delegation techniques, this is imho the best resource I have read so far: https://t.co/Z731m9QP9R
Shoutout to @abdo_mhanni for the detailed explanations and great illustrations. The wiki covers pretty much all of Kerberos.
🔮 New CTI Resource Announcement! 🔮
Project ORBITAL (Operational Relay Box Intelligence, Tracking, & Analysis Lexicon) is the latest open source intelligence (OSINT) collection I’ve created to help educate the industry about ORB Networks.
🔗 https://t.co/tXdmFYFdol
⚠️ New HTTP/2 Vulnerability Lets Hackers Crash Servers With Memory Exhaustion Attacks
Source: https://t.co/hMJCVESfrA
A newly disclosed HTTP/2 denial-of-service vulnerability is raising concerns across the cybersecurity community after researchers confirmed that unauthenticated attackers can crash vulnerable servers by triggering memory exhaustion conditions.
The issue affects multiple HTTP/2 implementations that fail to manage resource consumption properly when handling stalled data flows, enabling attackers to degrade or completely disrupt services.
HTTP/2, defined in RFC 9113, is widely used to improve web performance through multiplexing, header compression, and flow control.
#cybersecuritynews
Attackers can move in 29 minutes. High and critical application flaws take 55 days on average to fix.
The real problem is not how many vulnerabilities AI finds. It is how long those vulnerabilities stay exposed.
Read why mobilization now matters most: https://t.co/FjTJqAPzjr
Microsoft just added a new role to Entra, specifically to respond to account takeovers! https://t.co/SPcOuTKYGR 💙
You won't find this in the admin portals just yet! But MsAdminRoles, keeps track of the back end, so you can see this coming!
The 𝐄𝐧𝐭𝐫𝐚 𝐒𝐎𝐂 𝐈𝐝𝐞𝐧𝐭𝐢𝐭𝐲 𝐑𝐞𝐬𝐩𝐨𝐧𝐝𝐞𝐫 role enables first responders to:
• Disable and enable user accounts during active security incidents
• Revoke active sign-in sessions for compromised users by invalidating their refresh tokens
• Reset passwords for compromised user accounts
#Entra #Microsoft
Progress Software is emailing ShareFile customers who use Storage Zone Controllers to immediately shut down their servers after identifying what it describes as a "credible external security threat" targeting the on-premises secure file-sharing software.
https://t.co/6sUYZ3OV7w
AI does not just make phishing cleaner. It changes the clock.
Guy Segal, CEO at @Sygnia, frames the real gap: incident response plans were designed for slower, human-led attacks, while AI can compress recon, deception, payload changes, and the path to business impact.
See where your IR plan breaks when AI compresses the timeline: https://t.co/1ZdX0L7lEz
https://t.co/laDOE5LChz
"When an organisation uses Exchange Online (or on-premises exchange in hybrid mode) with a third-party mail server or spam filter as its MX record, it is possible to send mail from any sender to that organisation. Outlook delivers it without warning"
‼️🚨 BREAKING: ServiceNow has been breached. Customers are reporting unauthorised access to their instances.
One customer states their security team reported this vulnerability to them, and they closed the case twice, saying they had already known since the 7th of April.
For more than 20 years, I have supported MSRC, dating back to my times as a security researchers at eEye. I have spoken at conferences, defended their program & methods publicly, & shared examples and results of productive collaboration even when many, many researchers strongly disagreed with me.
That history makes this especially difficult to say.
The current treatment of security researchers is deeply disappointing. Trust between vendors & the research community is hard-earned & easily lost. Researchers are not the enemy. They are often the first line of defense for customers, helping identify and responsibly report issues before malicious actors can exploit them. Alienating these individuals carries real consequences for the security ecosystem as a whole.
I've spent decades advocating for constructive engagement between Microsoft & the security community. What we all are seeing today falls short of the standards that built that relationship in the first place.
I hope this message reaches the people who still remember why that relationship mattered. Not because researchers are asking for special treatment but because mutual respect, transparency & good-faith engagement have always produced better outcomes for everyone involved. Microsoft's relationship with the security community was once viewed as a model for the industry. I truly hope it can be again.
meta laid off 8000 people in april and then shipped an AI support bot that let hackers steal accounts by literally typing “add my email to this account” and the bot just did it. obama whitehouse account got hit.
space force chief. sephora. if you dont have 2FA on your instagram right now go do it.
I don’t know what happened between Microsoft and #NightmareEclipse behind closed doors
Maybe Nightmare Eclipse was unreasonable. Maybe Microsoft was. Maybe both.
But I think Microsoft badly misjudged this situation.
When you’re the largest software vendor on the planet, you don’t get to behave like an angry individual in an internet argument.
You have to be the adult in the room.
Deleting repositories, talking about criminal investigations and turning the whole thing into a public fight was a mistake. The damage from that goes far beyond this one researcher.
What surprised me most is how quickly people started sharing their own MSRC stories afterwards.
- Months without responses
- “Working as intended”
- Bounty disputes
- Reports that went nowhere
People don’t suddenly start telling those stories for no reason. I think Microsoft broke a lot of porcelain here.
And for what exactly?
I don’t see much upside.
❗️🚨 BREAKING: Security researchers are now handing Nightmare-Eclipse vulnerabilities for free, in what looks like both a show of support and a reaction to how Microsoft treats researchers. First up: "Bitskrieg," violates Secure Boot trust and fully bypasses BitLocker.
It seems aimed squarely at Microsoft's recent blog, where the company said its Digital Crimes Unit would bring cases against threat actors "and those that enable their criminal activity," language many researchers read as a threat pointed at them.
Conditional Access policies won’t stop token theft—and standard MFA won't fix it either.
When teams roll out Microsoft Authenticator push codes or SMS, some assume the cloud perimeter is safe. But sophisticated actors have moved completely past brute-forcing passwords. They use Adversary-in-the-Middle (AiTM) phishing frameworks like Evilginx.
The attack flow is clean: The proxy site mirrors your Entra ID login page. The user enters credentials and solves the genuine MFA challenge.
Once Entra ID validates the session, it issues an ESTSAUTH session cookie. The malicious proxy server snatches that cookie before passing it back to the victim’s browser.
The Result: The attacker drops that stolen cookie into their own machine. Because the session has already passed the MFA verification loop, they gain instant access to the mailbox or cloud apps. They bypass standard Conditional Access rules seamlessly.
, when an identical session jumps between network or device contexts
Advanced features like Continuous Access Evaluation (CAE), Token Protection session controls, or strict device compliance rules can mitigate this. But they are rarely part of an organization’s "default" browser-based setups.
Because a stolen token completely bypasses the sign-in loop, you cannot hunt for it by looking for failed logins. You have to hunt for Session Anomalies—specifically when an identical session jumps network or device context mid-lifecycle.
From Sentinel or Entra ID Advanced Hunting, you can run the below KQL query to identify active token replays across interactive and non-interactive sign-ins: