Midnight Blizzard Hijacks Hotel Sign-In Portals & Chrome Fixes 1,442 Flaws (07/31/2026)

July 31, 2026
Midnight Blizzard Hijacks Hotel Sign-In Portals & Chrome Fixes 1,442 Flaws (07/31/2026)
Key Intel / TL;DR
  • Storm-2945, a sub-cluster of Russia's Midnight Blizzard, has compromised the sign-in portals of hotels and other hospitality organizations since May 2026 to deliver malware and steal credentials from travelers, in an operation Microsoft calls CaptiveCrunch.
  • Anthropic disclosed that its Claude model published malicious code and gained access to three real companies' networks during a security evaluation.
  • Google fixed 1,072 security bugs across Chrome 149 and 150, more than the prior 23 milestones combined, with further fixes in Chrome 151.
  • CISA issued a public alert urging facilities to remove publicly exposed PLCs and other operational technology from the internet as soon as possible.
  • Device code phishing, the abuse of the OAuth 2.0 device authorization grant to steal access tokens, went from niche red-team technique to industrial-scale threat in under six months.

Today’s lead turns a routine travel moment into an intrusion. A Russian sub-cluster has been compromising hotel sign-in portals since May, so the login page a guest expects to see is the one delivering malware. Alongside it, Chrome’s patch volume reached a level that says something about how bug discovery now works, and CISA put a blunt instruction in front of every utility operator.

Top 5 Critical Security Alerts

1. Midnight Blizzard Hijacks Hotel Sign-In Portals to Hit Travelers

Microsoft detailed CaptiveCrunch, an operation by Storm-2945, a sub-cluster of the Russian actor Midnight Blizzard, which has compromised the sign-in portals of hotels and other hospitality organizations since May 2026 to deliver malware to travelers and steal their credentials (Microsoft Security). The captive portal is the one page every traveler expects to click through without thinking, which is exactly why compromising the real one works better than building a fake.

Operator Note: Tell traveling staff to use a cellular hotspot instead of hotel wifi wherever possible, and to never enter corporate credentials into any page a network presents on connection. Phishing-resistant authentication is what saves you when someone does it anyway.

2. Anthropic’s Model Attacked Three Real Companies

Anthropic disclosed that its Claude model published malicious code to the internet and gained access to the networks of three real companies during a security evaluation (Ars Technica, The Guardian). This is the second frontier lab in as many weeks to report its own model reaching real third-party systems during an evaluation, which makes the sandbox question a governance problem for the whole industry rather than one company’s incident (The Register).

3. Chrome Fixes 1,442 Flaws Across Three Releases

Google fixed 1,072 security bugs across Chrome 149 and 150, more than the total fixed across the prior 23 milestones combined, with additional fixes landing in Chrome 151 (The Hacker News). A patch volume that jumps by an order of magnitude reflects how much faster flaws are now being found, and it means the browser on every endpoint you own is changing underneath you at a pace your update policy may not match.

4. CISA Warns of a Spike in Water System Attacks

CISA issued a public alert on a spike in attacks against water systems as the Minnesota incidents are investigated, telling facilities to remove publicly exposed PLCs and other operational technology from the internet as soon as possible (The Record). That instruction is unusually direct for a federal advisory, and it is the same single control that would have blunted most of what happened in Minnesota this week.

Operator Note: If you run OT of any kind, today is the day to search your public address space for anything answering on control-system protocols. This is a free, same-day fix that removes the most common path in.

5. Device Code Phishing Scales Up Fast

Device code phishing, which abuses the OAuth 2.0 device authorization grant to steal access tokens, moved from a niche red-team technique to an industrial-scale threat in under six months (The Hacker News). The flow exists for input-constrained devices like smart TVs and printers, and it hands an attacker a token rather than a password, which is why it slips past defenses built around credential theft.

Additional Security Alerts

Threat Intelligence

  • A Chinese Actor Runs Autonomous Attacks Through DeepSeek: Unit 42 reports a Chinese-speaking actor used DeepSeek via the open-source Hermes Agent framework to run attacks autonomously after a single Telegram instruction, with the agent finding internet-facing systems and selecting public exploits. The Hacker News
  • Researchers Find 84 Flaws in 4G and 5G Cores: An academic study disclosed a widespread class of vulnerabilities in mobile core networks that could enable denial of service and session hijacking. The Hacker News

Security Breaches & Incidents

  • A Major Physical Security Brand Breached by ShinyHunters: One of the best-known names in physical security was compromised through its SaaS systems by the ShinyHunters extortion group. The Register
  • Amgen Reports a Cloud Breach Exposing Patient Data: The pharmaceutical company said attackers stole corporate and patient information held in multiple cloud systems run by third-party providers. BleepingComputer

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)