Threat Brief — 2026-08-01 — Hotel Wi-Fi RAT escalation
Executive summary: The most notable development today is an escalation in the hotel Wi-Fi compromise story: what began as Microsoft 365 credential phishing has now been confirmed to deliver CornFlake, a full surveillance RAT capable of webcam, microphone, and keystroke capture. No other fresh findings warrant new coverage — the Adform ad-script poisoning, Adobe Campaign Classic CVSS 10 RCE, and Arch Linux AUR package-takeover stories are re-reports of items already covered today with no genuine new developments.
Top items
- Hotel Wi-Fi attacks now deliver CornFlake surveillance RAT (developing). The hotel Wi-Fi DNS-hijack campaign first reported on 2026-07-24 by BleepingComputer as a Microsoft 365 phishing operation has escalated: Microsoft now confirms the fake browser-update chain delivers CornFlake, a remote access trojan that captures webcam images, microphone audio, and keystrokes. This shifts the threat from credential theft to full host surveillance, significantly raising the risk for travelling employees connecting to guest networks. (src: The Hacker News) — First reported 2026-07-24 by BleepingComputer.
- MariaDB transitions open-source code behind a paywall. MariaDB, the widely deployed MySQL fork, is ending open-source availability and moving code behind a paywall. While not a direct attack, this materially affects patch visibility and supply-chain trust for organisations relying on MariaDB as a drop-in MySQL replacement — security teams should assess whether their database stacks are impacted and review licensing alternatives. (src: SecurityLab)
Themes
Supply-chain trust erosion continues. The MariaDB paywall shift and the still-active Arch Linux AUR package-takeover story (first reported 2026-07-31) both underscore a persistent pattern: the open-source ecosystem that enterprises depend on is under pressure from both malicious actors and licensing model changes. Security teams should inventory critical open-source dependencies and evaluate redundancy.
