CaptiveCrunch Hotel Wi-Fi: Fake Logins and Malware Updates
Hotel Wi-Fi can deliver fake Microsoft logins or malware updates. Check what to do after a prompt, download, command, device code or Android APK.
News desk
Security incidents, exploited vulnerabilities, breach reports, malware campaigns, and urgent patch notes arranged for fast daily scanning.
September 13, 2026
Hotel Wi-Fi can deliver fake Microsoft logins or malware updates. Check what to do after a prompt, download, command, device code or Android APK.
CVE-2026-16232 is under active attack against internet-exposed Check Point management servers. Install the hotfix, restrict access, and check six IoCs.
CVE-2026-48294 in Adobe Acrobat for Chrome could expose rendered WhatsApp Web chats. Check the extension version and linked devices.
Chick-fil-A One accounts were accessed with reused passwords. Check rewards and payment settings, then change every account that shared the password.
AWS patched a Kiro IDE flaw that let hidden web text rewrite mcp.json and run commands without approval. Update Kiro and check MCP configurations…
HOLLOWGRAPH uses Microsoft 365 calendar events dated 2050 for command-and-control and file theft. Check Graph activity, logAzure.txt, and DNS telemetry.
CVE-2026-42533 affects NGINX map directives with regex captures. Check the exposure pattern and update to 1.30.4 or 1.31.3.
CERT-UA says UAC-0145 is using ClickFix pages, fake security tools, Signal lures, and Android malware against Ukrainian targets. Check the exact files, paths, and…
CVE-2026-63030 (wp2shell) gives anonymous attackers a route to code execution in WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1. Verify and update now.