Daily Security Intel

Archives
Log in
Subscribe
August 4, 2026

[SecurityIntel] 04 Aug | Midnight Blizzard Hijacks Hotel Wi-Fi Networks Globally

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Tuesday, August 04, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Midnight Blizzard Hijacks Hotel Wi-Fi Networks Globally

CRITICAL

5

C2 IPs

11

OTX IOCs

33

ARTICLES

■ ANALYST TLDR

Active exploitation of an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central servers and vulnerabilities in SonicWall SMA 1000 series VPN appliances highlights the severe risk to enterprise perimeters. Concurrently, Russian state-sponsored group Midnight Blizzard is targeting global hotel Wi-Fi networks to compromise Microsoft 365 accounts, while novel "Pass-ta-key" techniques exploit Google Password Manager to bypass passkey-based MFA. Organizations must prioritize patching edge appliances and enforcing secure remote access policies for traveling staff.

■ CRITICAL STORIES

INFO#1

N-able warns of N-central auth bypass flaw exploited in attacks

Threat actors are actively exploiting CVE-2026-18577, an authentication bypass vulnerability affecting both hosted and on-premises N-central servers, after bypassing a previous patch attempt. This allows attackers to gain unauthorized administrative access to managed service provider (MSP) environments.

INFO#2

Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

Russian state-sponsored threat actor Midnight Blizzard (APT29) is compromising hotel Wi-Fi networks globally to target high-profile travelers, deploying custom malware to harvest credentials and hijack Microsoft 365 accounts.

INFO#3

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Security researchers have disclosed "Pass-ta-key" attacks where malware running on compromised Windows devices can abuse Google Password Manager's synced passkeys. By exploiting relying parties' failure to validate the "User Verified" flag, attackers bypass MFA without triggering any user prompts.

INFO#4

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

INC Ransomware has become the primary threat actor actively exploiting recently disclosed security vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances to breach corporate networks and deploy ransomware.

■ CVEs IDENTIFIED

CVE-2026-18577

N-able N-central Server — Authentication Bypass

Critical

[CVE-TBD]

SonicWall Secure Mobile Access (SMA) 1000 Series — Security Bypass / Remote Code Execution (exploited by INC Ransomware)

Critical

[CVE-TBD]

Google Password Manager (Chrome) — Passkey Hijacking / Authentication Bypass

High

[CVE-TBD]

Thermo Fisher Applied Biosystems Human Identification Software — DNA File Tampering / Data Integrity Bypass

High

■ THREAT ACTORS

Midnight Blizzard (APT29)

Nation-State (Russia)

Compromising hotel Wi-Fi networks globally to steal credentials and hijack Microsoft 365 accounts.

INC Ransomware

Cybercrime / Ransomware

Actively exploiting SonicWall SMA 1000 series VPN vulnerabilities to gain initial access.

ExfilSquad

Cybercrime / Hacktivism

Leaked contact data of over 100,000 UK police officers and staff from the Police National Legal Database (PNLD).

■ ATT&CK TTPs

T1133
External Remote Services | INC Ransomware exploiting SonicWall SMA 1000 VPNs.
T1556
Modify Authentication Process | Google Password Manager passkey bypass ("Pass-ta-key") neglecting User Verified flags.
T1557.002
Adversary-in-the-Middle: Wi-Fi Spoofing | Midnight Blizzard hijacking hotel Wi-Fi networks to intercept traffic and steal M365 credentials.
T1195.002
Supply Chain Compromise: Malicious Software Dependency | 18 malicious npm packages targeting Alibaba developer tools.
T1027.011
Obfuscated Files or Information: Steganography | DOUBLECUP ClickFix service hiding malicious code in browser-cached PNG images.
T1204.002
User Execution: Malicious File | Fake Roblox Xeno script launchers executing infostealers on victim machines.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

N-able N-central Server — Authentication bypass vulnerability (CVE-2026-18577) actively exploited in the wild due to patch bypass — BleepingComputer

[P1 PATCH NOW]≤24h

SonicWall Secure Mobile Access (SMA) 1000 Series — Actively exploited by INC Ransomware to compromise networks — The Hacker News

[P2 PATCH NOW]≤72h

Thermo Fisher Applied Biosystems Human Identification Software — Flaw allows nearly undetectable DNA file tampering before analysis — The Hacker News

[P2 PATCH NOW]≤72h

Google Password Manager / Chrome — Passkey extraction and MFA bypass vulnerability ("Pass-ta-key") — Unit 42

■ RECOMMENDED ACTIONS TODAY

1[P1] Immediately apply the latest security patches for N-able N-central (CVE-2026-18577) to prevent active authentication bypass exploitation.
2[P1] Patch all SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances immediately to mitigate active exploitation by the INC Ransomware group.
3[P2] Implement strict validation of the "User Verified" flag for passkey authentications on all relying party applications to block "Pass-ta-key" bypass techniques.
4[P2] Apply the July 31 security update from Thermo Fisher Scientific for Applied Biosystems human identification software to prevent unauthorized DNA file tampering.
5[P2] Enforce corporate VPN usage and multi-factor authentication (MFA) for all employees traveling and utilizing untrusted hotel Wi-Fi networks to counter Midnight Blizzard campaigns.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
Older → [SecurityIntel] 03 Aug | COLDCARD Wallet RNG Flaw Enables $88M Theft
Powered by Buttondown, the easiest way to start and grow your newsletter.