🟠 High | Source: The Register — Security
Russia’s foreign intelligence service (SVR) has been caught compromising public Wi-Fi captive portals — the login pages seen in hotels, airports, and cafés — to deliver keyloggers, steal authentication tokens, and conduct audio-visual surveillance on connected users. The campaign specifically targets the hospitality sector, putting business travellers and remote workers at heightened risk. This represents a significant shift in tradecraft, weaponising ubiquitous public infrastructure rather than targeting enterprise networks directly.
Security Architect’s Take: Mandate the use of always-on VPN or Zero Trust Network Access (ZTNA) solutions for all corporate devices before any traffic is permitted over public Wi-Fi, and explicitly block captive portal authentication flows from occurring outside a sandboxed browser context. Review travel security policies to ensure remote workers and executives are briefed on the risk of connecting to hospitality networks without these controls in place.
Original advisory: Russian spies turn public Wi-Fi into malware delivery systems