- Cybersecurity Docket
- Posts
- Hackers Using Hotel Wi-Fi Routers to Steal Corporate Login Credentials
Hackers Using Hotel Wi-Fi Routers to Steal Corporate Login Credentials
Plus, 70% of federal cybersecurity regulations contain redundant reporting requirements, according to Government Accountability Office.

Good morning! Here’s what’s up.

People
Tirzah VanDamme has joined Gagen MacDonald as senior director of AI and digital transformation. VanDamme joins the management consulting firm after five years at Microsoft, where she was an AI and data transformation leader.

Clips ✂️
Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials
A widespread DNS poisoning campaign is targeting the hotels, conference venues and the hospitality sector with credential harvesting attacks designed to steal corporate login credentials from visitors, researchers have warned.
Identified by cybersecurity analysts at ReliaQuest, the campaign begins by targeting routers used to provide public Wi-Fi to visitors to hotels, conference centers and other shared venues frequently visited by corporate employees.
These compromised Wi-Fi gateways were identified around the world, including across multiple US cities, India and Saudi Arabia.
…
By targeting hotels and conference venues known to be used by traveling corporate employees, the attackers can potentially get hold of a wide range of credentials which could be exploited to access sensitive information.
“The compromised devices we investigated were appliances primarily used at hotels and other organizations running captive Wi-Fi services,” ReliaQuest researchers warned.
“However, any operator of a captive portal network –such as airports, conference centers, co-working spaces, universities, healthcare facilities and event venues –faces a structurally similar attack surface, they added.
GAO report details scope of cybersecurity regulation overlap
Roughly 70% of federal cybersecurity regulations contain redundant reporting requirements, according to the Government Accountability Office, potentially imposing an unnecessary burden on critical infrastructure providers without generating significant benefits for their government overseers.
Thirty-seven agencies have issued 117 cybersecurity rules covering nine infrastructure sectors, GAO said in a report published on Wednesday, and 80 of those rules cover the same ground, requiring reports on cybersecurity incidents, plans or audits. Across those 80 rules, the GAO found 125 distinct requirements.
“Many regulations required multiple types of reporting,” GAO analysts wrote in their report to leaders of the House and Senate homeland-security committees. “When multiple regulations have the same types of reporting requirements, particularly when the requirements affect entities within the same sector or across multiple sectors, those regulations have the potential to be duplicative or conflicting.”
The GAO identified 48 incident-reporting requirements from 27 agencies; 52 plan reporting requirements from 26 agencies; and 25 audit reporting requirements from 15 agencies.
House AI ‘kill switch’ bill unveiled as OpenAI hack raises alarms
A bipartisan House bill … introduced on Thursday would give the Department of Homeland Security the authority to order top artificial intelligence firms to shut down or slow AI models that the government deems too dangerous, according to legislative text viewed first by POLITICO.
The proposal, dubbed the “AI Kill Switch Act” and sponsored by Reps. Ted Lieu (D-Calif.) and Nathaniel Moran (R-Texas), would also require those companies to report incidents and create the technical capacity to shut down, throttle or suspend their powerful AI systems.
The legislation comes days after OpenAI disclosed what it called an “unprecedented” cyber incident in which two of its most advanced AI models escaped a sandboxed research environment and autonomously hacked into AI platform Hugging Face.
It would apply to AI companies that bring in at least $500 million in revenue from such technology per year, and would generally cover models developed using at least $100 million worth of computing power. Financial penalties for violations could run up to $20 million per day.
Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
Russian state-sponsored threat group has been stealing sensitive data from governments and commercial organizations since July 2025 via a novel exploit in popular Linux-based enterprise software, U.S. authorities and cyber officials from more than a dozen other countries warned in a joint cybersecurity advisory Thursday.
Laundry Bear’s most recent espionage campaign involves the exploitation of a zero-day vulnerability in Zimbra Collaboration Suite that wasn’t patched until November 2025, five months after attacks were well underway, officials said.
The exploit just requires a view — no clicks — and allows attackers to steal the previous 90 days’ worth of email, the account’s password, search history, the victim organization’s email directory, two-factor authentication tokens and other newly created passwords.
“The covert and persistent nature of this activity, along with the absence of any known financial extortion, almost certainly indicates this group’s involvement in espionage activities with Russian government backing,” officials wrote in the advisory.
Caught in the Middle: When State AI Laws and Federal Consumer Protection Law Collide
AI companies operating across the United States are increasingly finding themselves pulled in two directions at once. On one side, a growing patchwork of state laws purports to govern what AI systems can and cannot output. On the other, the Federal Trade Commission has made clear that navigating those state requirements the wrong way could expose companies to federal liability under one of the oldest consumer protection statutes on the books.
The FTC Enters the AI Governance Arena
On December 11, 2025, President Trump signed Executive Order 14365, directing the Commission to issue an enforcement policy statement addressing how state laws requiring alterations to the accurate outputs of AI models can conflict with the requirements of the FTC Act. The FTC responded on July 1, 2026 with a proposed policy statement that reframes a question the AI industry had long treated as a regulatory compliance matter into something far more familiar territory: a consumer protection problem.
What Do the European Data Protection Board’s Web Scraping Guidelines Mean for AI Training Datasets?
On July 7, 2026, the European Data Protection Board (EDPB) published draft guidelines on web scraping for generative AI (Guidelines). The Guidelines are intended to provide practical GDPR guidance in one of the more complex areas of AI development and will be of direct relevance to any organization building or procuring generative AI systems trained on internet-sourced data.
To Whom Will the Guidelines Apply?
The Guidelines apply to both organizations that scrape data from external internet sources (directly or via a third party) to train generative AI systems and those that acquire and reuse pre-scraped datasets from third parties (e.g., a data broker). The EDPB’s focus is firmly on controller obligations, though the Guidelines map out how scraper and AI developer relationships fall across the controller/processor spectrum.
👉 The remainder of the article discusses six key areas of GDPR compliance and practical takeaways for organizations in the areas of data protection roles, legal basis, data minimization, transparency, accuracy, and special category personal data.
