discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report.

By Swati Khandelwal·Aug 1·thehackernews.com·2 min read

Intelligence analysis by Llama

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
Image: thehackernews.com

A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes. Microsoft has observed the traffic manipulation since early May across hospitality networks in several countries.

Why it matters

This story matters to someone following Security because it highlights the risks of hijacked hotel Wi-Fi and the potential for surveillance malware to be delivered through fake updates.

Imagine you're at a hotel and you connect to their Wi-Fi. But what if someone had hacked into the hotel's Wi-Fi and was sending you fake updates to install malware on your device? That's what happened in this case, where a fake browser update was used to deliver a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes. It's like someone is watching you through your webcam and listening to your conversations.

Analysis

A $60B Vote of Confidence

The recent report by Microsoft highlights the risks of hijacked hotel Wi-Fi and the potential for surveillance malware to be delivered through fake updates. The fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes. This is a significant concern for travelers and hotel guests, as it highlights the potential for malicious actors to compromise hotel networks and deliver malware to unsuspecting users.

Why Cursor?

The report by Microsoft also highlights the potential for malicious actors to use fake browser updates to deliver malware. The fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes. This is a significant concern for travelers and hotel guests, as it highlights the potential for malicious actors to compromise hotel networks and deliver malware to unsuspecting users.

The Road Ahead

The report by Microsoft highlights the need for travelers and hotel guests to be aware of the risks of hijacked hotel Wi-Fi and the potential for surveillance malware to be delivered through fake updates. It is essential for travelers and hotel guests to use private connections and reject software updates, certificates, browser updates, troubleshooting tools, or security utilities offered through captive portals. Additionally, Microsoft recommends blocking the device code authentication flow through Conditional Access wherever it is not needed.

Key points

  • A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes.
  • Microsoft has observed the traffic manipulation since early May across hospitality networks in several countries.
  • The fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes.
  • Microsoft recommends blocking the device code authentication flow through Conditional Access wherever it is not needed.
  • ReliaQuest recommends an always-on, full-tunnel virtual private network (VPN), which sends DNS queries through corporate resolvers before the venue's gateway can answer them.
The Upside

If this development plays out positively, it could lead to increased awareness among travelers and hotel guests about the risks of hijacked hotel Wi-Fi and the potential for surveillance malware to be delivered through fake updates. This could lead to a decrease in the number of people falling victim to these types of attacks.

The Downside

The realistic downside risks or failure modes of this development include the potential for malicious actors to continue compromising hotel networks and delivering malware to unsuspecting users. This could lead to a significant increase in the number of people falling victim to these types of attacks.

Market signals

XAU
  • XAU Escalation drives safe-haven demand for gold, per the article's framing of investor reaction.

AI-generated analysis of potential market relevance. Not financial advice.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagscyber-espionagemalwarenetwork-securityphishingwi-fi-securitywindows-security

Author

Swati Khandelwal

Intelligence analysis by

Llama

Published

Aug 1, 2026

Source

thehackernews.com

Share

Topics

cyber-espionagemalwarenetwork-securityphishingwi-fi-securitywindows-security

Related

More from this desk

Aug 1·thehackernews.com

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

Hackers modified a JavaScript file served by Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities.

Aug 1·thehackernews.com

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution.

Jul 31·bleepingcomputer.com

Amgen says cloud data breach exposed patient health, proprietary info

Pharmaceutical company Amgen suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers.

Jul 31·bleepingcomputer.com

Online ad firm Adform’s script compromised to steal cryptocurrency

Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors’ clipboards with ones controlled by an attacker.