ReliaQuest DNS poisoning mitigation guidance
Advisory/Mitigation
Summary
Hide ▲
Show ▼
ReliaQuest issued mitigation advice for DNS poisoning that can redirect legitimate traffic and expose endpoints to credential-harvesting. The guidance targets operators of hotel and other captive Wi‑Fi environments facing the same attack surface. It recommends preventing the poisoning from reaching endpoints, eliminating the attack surface, and detecting credential-harvesting activity if it occurs.
Related Happenings
Midnight Blizzard CaptiveCrunch hospitality Wi-Fi phishing campaign
Campaign
H score37
First: 04.08.2026 03:17
Last: 04.08.2026 03:17
Sources 1
About this happening:
Microsoft linked CaptiveCrunch to Midnight Blizzard / APT29, a global operation that abuses hospitality Wi‑Fi to steal Microsoft 365 accounts and deliver malware....
Midnight Blizzard CaptiveCrunch hospitality Wi-Fi phishing campaign
CampaignAbout this happening: Microsoft linked CaptiveCrunch to Midnight Blizzard / APT29, a global operation that abuses hospitality Wi‑Fi to steal Microsoft 365 accounts and deliver malware....
CaptiveCrunch Storm-2945 hotel Wi-Fi redirection campaign
Campaign
H score40
First: 01.08.2026 09:29
Last: 01.08.2026 09:29
Sources 1
About this happening:
Microsoft linked the CaptiveCrunch campaign to Midnight Blizzard / APT29 / Storm-2945, saying it has been active since early May and targets hospitality Wi‑Fi ne...
CaptiveCrunch Storm-2945 hotel Wi-Fi redirection campaign
CampaignAbout this happening: Microsoft linked the CaptiveCrunch campaign to Midnight Blizzard / APT29 / Storm-2945, saying it has been active since early May and targets hospitality Wi‑Fi ne...
DNS poisoning campaign targeting captive Wi‑Fi routers to harvest corporate credentials
Campaign
H score34
First: 24.07.2026 15:00
Last: 24.07.2026 15:00
Sources 1
How related:
A widespread DNS poisoning campaign is targeting the hotels, conference venues and the hospitality sector with credential harvesting attacks designed to steal corporate login credentials from visitors, researchers have warned.
About this happening:
An ongoing DNS poisoning campaign is redirecting traffic from hotel and conference venue Wi‑Fi routers to harvest corporate login credentials, putting traveling employ...
DNS poisoning campaign targeting captive Wi‑Fi routers to harvest corporate credentials
CampaignHow related: A widespread DNS poisoning campaign is targeting the hotels, conference venues and the hospitality sector with credential harvesting attacks designed to steal corporate login credentials from visitors, researchers have warned.
About this happening: An ongoing DNS poisoning campaign is redirecting traffic from hotel and conference venue Wi‑Fi routers to harvest corporate login credentials, putting traveling employ...
Timeline
-
24.07.2026 15:00 2 articles · 13d ago
ReliaQuest issues DNS poisoning prevention advice for captive Wi-Fi operators
Mitigation Patch UpdateReliaQuest advised operators of hotel Wi-Fi, conference venues, and other captive Wi-Fi environments to stop DNS poisoning before it reaches endpoints, reduce the exposed attack surface, and detect credential-harvesting activity on compromised networks.
Show sources
- Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials From Visitors — www.infosecurity-magazine.com — 24.07.2026 15:00
- Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials From Visitors — www.infosecurity-magazine.com — 24.07.2026 15:00