From PC World: In a recent Microsoft Security Blog post, the company has raised awareness of a widespread attack campaign called CaptiveCrunch. In short, Russian hackers are using manipulated DNS queries to redirect users to phishing sites that mimic Microsoft’s official online services. As a result, Microsoft is warning against the use of public Wi-Fi networks.
With these fake phishing sites, the attackers are attempting to intercept and steal login credentials for Microsoft accounts. Some security researchers previously published a warning to this effect back in July, and now Microsoft is supplementing that report with its own new information based on what it has been monitoring since May 2026.
According to the report, the attackers redirect users—for example, those who are logging into their Microsoft accounts via a hotel Wi-Fi network—to imitation phishing sites. There, the attackers capture device and OAuth codes, which they can use to take over said Microsoft accounts.
View: Full Article