IT Starts with CareNeed support?
Talk to KPTech1300 303 173

Microsoft Threat Intelligence has reported an active campaign it calls CaptiveCrunch, associated with a sub-cluster of Midnight Blizzard. The campaign has manipulated DNS and HTTP traffic on networks served by captive portals, including travel and hospitality environments, to redirect users toward attacker-controlled infrastructure.

Why this matters

Travellers often expect airport, hotel and venue Wi-Fi to redirect them to a sign-in page. That normal behaviour can make a malicious redirect harder to spot. Microsoft says the campaign has also used lookalike Microsoft domains and adversary-in-the-middle phishing techniques, including abuse of Microsoft Entra device-code authentication.

Recommended response

If you think a staff member has entered credentials into a suspicious page, change the password, revoke active sessions and have the account reviewed as soon as possible.

Source: Microsoft Threat Intelligence, 31 July 2026. This KPTech article is a plain-English summary with practical response guidance.

Phishing continues to evolve beyond the obvious fake-email link. Microsoft’s Q2 2026 threat review highlights QR-code lures, CAPTCHA-gated phishing pages, business email compromise and increasing use of Microsoft Teams for social engineering.

What businesses should watch for

Recommended response

Train staff to verify unusual requests through a second channel, protect Microsoft 365 with MFA, review external Teams access, and use modern email security controls. Payment and bank-detail changes should always be independently verified using a known phone number.

Source: Microsoft Threat Intelligence, Email threat landscape Q2 2026, published 23 July 2026.

Microsoft Threat Intelligence is tracking DeadLock as an emerging financially motivated ransomware operation. The group uses a Rust-based encryptor and combines file encryption with data theft and extortion pressure.

The practical lesson

The ransomware name may change, but the defensive priorities remain consistent: reduce the chance of initial access, limit how far an attacker can move, and make recovery possible without relying on the attacker.

Recommended response

Backups are particularly important, but they should be tested. A backup that has never been restored is only an assumption.

Source: Microsoft Threat Intelligence, DeadLock ransomware analysis, 10 August 2026.

Many successful cyberattacks do not begin with a mysterious new zero-day. They begin with an internet-facing firewall, VPN, server or application that is running a vulnerability already known to be exploited in the real world.

CISA maintains a Known Exploited Vulnerabilities catalogue specifically to identify vulnerabilities with evidence of active exploitation.

Recommended response

For small businesses, good patch management is one of the highest-value security controls because it removes known paths attackers are already using.

Source: CISA Known Exploited Vulnerabilities Catalog and Cybersecurity Advisories.