Observed Signal · Jul 28, 2026 · Threat Report · Source: DEV Community · Impact: 3/5 · Sentiment: Neutral
Public Wi‑Fi DNS Poisoning Hijacks Microsoft 365 Sessions
Security researchers report a campaign that compromises public Wi‑Fi gateway management interfaces (e.g., in hotels, conference centers) to forge DNS responses and WPAD proxy settings, redirecting users to fake Microsoft sign‑in pages. Attackers exploit the OAuth device‑code flow (Microsoft Entra ID) and WPAD to obtain MFA‑authenticated tokens and access Microsoft 365 sessions without installing malware on victims' devices. Activity has been observed since June 2026 in the US, India, and Saudi Arabia. Detection techniques include monitoring for IOC IPs/domains, PAC/WPAD downloads (WinHttpAutoProxySvc), device‑code sign‑ins, and unusual post‑MFA access from unknown IPs/locations. Primary coverage cites SecurityWeek and a detailed ReliaQuest threat spotlight as sources.
This threat targets identity and session tokens (Microsoft 365), affecting enterprise identity security and detection practices; relevant to organizations that rely on device‑code/OAuth flows and public Wi‑Fi protections, but it is a security threat rather than an industry structural change.
Track Microsoft Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Attackers compromise public Wi‑Fi gateway management interfaces to return fake DNS responses and control WPAD/DHCP option 252.
- The campaign abuses the OAuth device‑code flow (Microsoft Entra ID) to obtain MFA‑authenticated Microsoft 365 tokens without capturing passwords.
- Activity was observed since June 2026 in the US, India, and Saudi Arabia; IOCs include IPs (e.g., 38.146.28.75) and domains (e.g., m365-owa.com).
- No malware is required on victim devices; successful exploitation depends on gateway admin access, unencrypted DNS or plaintext fallback, and device‑code/conditional access policies.
Connected Companies & Entities
1 Entity mapped“Related Entities: Microsoft 365, Entra ID device-code flow, DNS poisoning, AiTM, WPAD, captive portal, FrostArmada, APT28 (attribution uncon...”
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
FBI warns Microsoft 365 users about Kali365 phishing
The U.S. FBI has issued a public advisory warning Microsoft 365 users about a new phishing platform called Kali365. First observed in April and reported to circulate mainly on Telegram, Kali365 provides Phishing-as-a-Service tooling that helps attackers harvest OAuth access and refresh tokens via a device-code phishing flow. According to the FBI, criminals can use those tokens to bypass passwords and multi-factor authentication and access Microsoft 365 services such as Outlook, Teams and OneDrive. The FBI recommends restricting or disabling OAuth device-code flows except where absolutely necessary and following other hardening measures to reduce exposure.
Session Hijacking: Cookie Theft Bypasses Two-Factor Authentication
The article explains session hijacking by cookie/theft of session tokens as a rapidly growing identity attack in 2026. Infostealer malware (e.g., RedLine, Raccoon, Lumma, Vidar) exfiltrates entire browser cookie stores and related credentials; those datasets—called “stealer logs”—appear on Telegram channels and dark‑web marketplaces. SpyCloud reports a 58% rise in infostealer infections and over 2.1 billion stolen cookie records. Google’s Threat Analysis Group says session token theft now causes more account takeovers than phishing, and Microsoft confirmed AiTM phishing kits plus session token theft drove a wave of enterprise compromises in early 2026. Because stolen cookies represent already-authenticated sessions, two‑factor authentication often cannot stop these attacks. Recommended protections include patching devices, using antivirus, logging out of sessions, clearing cookies, avoiding public Wi‑Fi or using a VPN, and adopting device‑bound or token‑binding session designs.
Microsoft npm Packages Backdoored; AI Agents Trigger Credential Stealer
Seventy-three cryptographically signed Microsoft npm packages were compromised with a credential‑stealing worm called “Miasma,” derived from an open-source toolkit. The malware deploys a small (≈28 KB) payload that automatically harvests credentials from cloud providers (AWS, Azure, GCP), Kubernetes, many developer tool configs and password managers, and then spreads laterally through cloud infrastructure. The payload is triggered simply by opening a package inside AI coding agents and IDE integrations (examples named: Claude Code, Gemini CLI, Cursor, VS Code). Attackers used stolen Microsoft publisher credentials to publish malicious builds that carried valid SLSA provenance attestations, defeating provenance-only detection. The same Microsoft account had previously been compromised in May 2026 (durabletask Python SDK on PyPI), raising concerns about credential rotation and remediation.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
