Dev.to
7/28/2026

The original title is 11 words: "Public Wi‑Fi DNS Poisoning: Hijacking Microsoft 365 Sessions of Business Travelers"
Original: Public Wi‑Fi DNS Poisoning: Hijacking Microsoft 365 Sessions of Business Travelers
Short summary
Attackers are compromising public Wi-Fi gateways at hotels and conference centers to forge DNS responses and hijack Microsoft 365 sessions. The attack uses WPAD proxies and device-code authentication to steal MFA-authenticated OAuth tokens without sending phishing emails. Defenders should enforce always-on VPN, disable WPAD, block device-code flow in Entra ID, and require phishing-resistant MFA.
- •Compromised Wi-Fi gateways forge DNS to redirect users to fake Microsoft login pages
- •Device-code flow abuse steals MFA-authenticated OAuth tokens without malware
- •Mitigation: always-on VPN, strict DoH/DoT, disable WPAD, block device-code flow
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



