Russian ISP compromise
2025-08-01 17:47:28.294657+02 by Dan Lyke 0 comments
Microsoft catches Russian hackers "Secret Blizzard" targeting foreign embassies. Looks like it uses an ISP intercept to pop up the captive portal redirect thing and try to get people to install a .exe that mucks with the root CA.
Microsoft Security: Frozen in transit: Secret Blizzard’s AiTM campaign against diplomats