Device Code Phishing Is How Midnight Blizzard Beat MFA on Hotel Wi-Fi
A Storm-2945 campaign layers device code phishing onto hijacked hotel Wi-Fi to bypass MFA on Microsoft 365 accounts. Here’s how it works and how to shut it off.
A Storm-2945 campaign layers device code phishing onto hijacked hotel Wi-Fi to bypass MFA on Microsoft 365 accounts. Here’s how it works and how to shut it off.
CVE-2026-16232 lets an unauthenticated attacker seize full admin control of Check Point’s management console. Check Point confirms in-the-wild attacks, and a Rapid7 PoC is now public.