✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Travel/Tourism
Breach intelligence, attack campaigns, and threat reports targeting the Travel/Tourism sector.
Explore Other Sectors
Travel/Tourism Threat Reports
Hotel Wi-Fi Attacks Deploy Custom Malware to Compromise Microsoft 365 Accounts
In May 2026, Microsoft identified a sophisticated cyberattack campaign, dubbed 'CaptiveCrunch,' targeting hotel and conference center Wi-Fi networks globally. Attributed to the Russian state-sponsored group Midnight Blizzard (APT29), the attackers compromised captive portal equipment to manipulate DNS and HTTP traffic. This allowed them to redirect users to phishing pages mimicking Microsoft 365 login portals, leading to credential theft. Additionally, they deployed custom malware families, CornFlake and ChocoShell, enabling persistent access, surveillance, and data exfiltration. This incident underscores the evolving tactics of nation-state actors in exploiting trusted public networks to infiltrate corporate environments. The use of custom malware and advanced phishing techniques highlights the need for heightened vigilance and robust security measures when accessing corporate resources over public Wi-Fi.
5 days ago
Kill Chain
SpiceJet Online Booking System Vulnerabilities Expose Passenger Data
In April 2026, two critical vulnerabilities were identified in SpiceJet's Online Booking System: CVE-2026-6375 and CVE-2026-6376. These flaws allowed unauthenticated users to access passenger name records (PNRs) and full booking details using only a PNR and last name, due to missing authorization checks and authentication mechanisms. This exposed sensitive personal and travel information to potential exploitation. ([securityvulnerability.io](https://securityvulnerability.io/vulnerability/CVE-2026-6376?utm_source=openai)) The incident underscores the importance of robust access controls in online systems, especially in the transportation sector. Organizations must prioritize securing sensitive customer data to prevent unauthorized access and potential misuse.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports