Observed Signal · Jul 28, 2026 · Threat Report · Source: DEV Community · Impact: 3/5 · Sentiment: Neutral

Public Wi‑Fi DNS Poisoning Hijacks Microsoft 365 Sessions

Executive Signal Summary

Security researchers report a campaign that compromises public Wi‑Fi gateway management interfaces (e.g., in hotels, conference centers) to forge DNS responses and WPAD proxy settings, redirecting users to fake Microsoft sign‑in pages. Attackers exploit the OAuth device‑code flow (Microsoft Entra ID) and WPAD to obtain MFA‑authenticated tokens and access Microsoft 365 sessions without installing malware on victims' devices. Activity has been observed since June 2026 in the US, India, and Saudi Arabia. Detection techniques include monitoring for IOC IPs/domains, PAC/WPAD downloads (WinHttpAutoProxySvc), device‑code sign‑ins, and unusual post‑MFA access from unknown IPs/locations. Primary coverage cites SecurityWeek and a detailed ReliaQuest threat spotlight as sources.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

This threat targets identity and session tokens (Microsoft 365), affecting enterprise identity security and detection practices; relevant to organizations that rely on device‑code/OAuth flows and public Wi‑Fi protections, but it is a security threat rather than an industry structural change.

SIGNAL RADAR

Track Microsoft Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Attackers compromise public Wi‑Fi gateway management interfaces to return fake DNS responses and control WPAD/DHCP option 252.
  • The campaign abuses the OAuth device‑code flow (Microsoft Entra ID) to obtain MFA‑authenticated Microsoft 365 tokens without capturing passwords.
  • Activity was observed since June 2026 in the US, India, and Saudi Arabia; IOCs include IPs (e.g., 38.146.28.75) and domains (e.g., m365-owa.com).
  • No malware is required on victim devices; successful exploitation depends on gateway admin access, unencrypted DNS or plaintext fallback, and device‑code/conditional access policies.

Connected Companies & Entities

1 Entity mapped

“Related Entities: Microsoft 365, Entra ID device-code flow, DNS poisoning, AiTM, WPAD, captive portal, FrostArmada, APT28 (attribution uncon...”

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Jul 28, 2026
Original Coverage Title: “Public Wi‑Fi DNS Poisoning: Hijacking Microsoft 365 Sessions of Business Travelers”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

IdentityMay 28, 2026

FBI warns Microsoft 365 users about Kali365 phishing

The U.S. FBI has issued a public advisory warning Microsoft 365 users about a new phishing platform called Kali365. First observed in April and reported to circulate mainly on Telegram, Kali365 provides Phishing-as-a-Service tooling that helps attackers harvest OAuth access and refresh tokens via a device-code phishing flow. According to the FBI, criminals can use those tokens to bypass passwords and multi-factor authentication and access Microsoft 365 services such as Outlook, Teams and OneDrive. The FBI recommends restricting or disabling OAuth device-code flows except where absolutely necessary and following other hardening measures to reduce exposure.

Read assessment
IdentityJul 6, 2026

Session Hijacking: Cookie Theft Bypasses Two-Factor Authentication

The article explains session hijacking by cookie/theft of session tokens as a rapidly growing identity attack in 2026. Infostealer malware (e.g., RedLine, Raccoon, Lumma, Vidar) exfiltrates entire browser cookie stores and related credentials; those datasets—called “stealer logs”—appear on Telegram channels and dark‑web marketplaces. SpyCloud reports a 58% rise in infostealer infections and over 2.1 billion stolen cookie records. Google’s Threat Analysis Group says session token theft now causes more account takeovers than phishing, and Microsoft confirmed AiTM phishing kits plus session token theft drove a wave of enterprise compromises in early 2026. Because stolen cookies represent already-authenticated sessions, two‑factor authentication often cannot stop these attacks. Recommended protections include patching devices, using antivirus, logging out of sessions, clearing cookies, avoiding public Wi‑Fi or using a VPN, and adopting device‑bound or token‑binding session designs.

Read assessment
Supply-Chain SecurityJun 9, 2026

Microsoft npm Packages Backdoored; AI Agents Trigger Credential Stealer

Seventy-three cryptographically signed Microsoft npm packages were compromised with a credential‑stealing worm called “Miasma,” derived from an open-source toolkit. The malware deploys a small (≈28 KB) payload that automatically harvests credentials from cloud providers (AWS, Azure, GCP), Kubernetes, many developer tool configs and password managers, and then spreads laterally through cloud infrastructure. The payload is triggered simply by opening a package inside AI coding agents and IDE integrations (examples named: Claude Code, Gemini CLI, Cursor, VS Code). Attackers used stolen Microsoft publisher credentials to publish malicious builds that carried valid SLSA provenance attestations, defeating provenance-only detection. The same Microsoft account had previously been compromised in May 2026 (durabletask Python SDK on PyPI), raising concerns about credential rotation and remediation.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.