Back to feed
Dev.to
Dev.to
7/28/2026
The original title is 11 words: "Public Wi‑Fi DNS Poisoning: Hijacking Microsoft 365 Sessions of Business Travelers"

The original title is 11 words: "Public Wi‑Fi DNS Poisoning: Hijacking Microsoft 365 Sessions of Business Travelers"

Original: Public Wi‑Fi DNS Poisoning: Hijacking Microsoft 365 Sessions of Business Travelers

Short summary

Attackers are compromising public Wi-Fi gateways at hotels and conference centers to forge DNS responses and hijack Microsoft 365 sessions. The attack uses WPAD proxies and device-code authentication to steal MFA-authenticated OAuth tokens without sending phishing emails. Defenders should enforce always-on VPN, disable WPAD, block device-code flow in Entra ID, and require phishing-resistant MFA.

  • Compromised Wi-Fi gateways forge DNS to redirect users to fake Microsoft login pages
  • Device-code flow abuse steals MFA-authenticated OAuth tokens without malware
  • Mitigation: always-on VPN, strict DoH/DoT, disable WPAD, block device-code flow

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more