Breaking
August 17, 2026

Public Wi-Fi just got riskier. Follow these 4 security tips | usagoldmines.com

You probably trust public Wi-Fi. But you shouldn’t–at least not completely and not without any safeguards.

A new kind of attack is the latest reminder of this. As detailed by Microsoft, hackers have been infiltrating login portals at hotels. Previously, such hijacking was used to redirect users to fake Microsoft 365 login pages or subvert Microsoft’s corporate-grade authentication method (Entra ID). But now there’s a more dangerous variation that tricks people into installing malware.

Welcome to Safe Mode, your weekly report for pressing security and privacy news—and what steps to take next. Want this newsletter to come directly to your inbox? Sign up on our website

It relies on a technique called ClickFix, where a popup appears with instructions that claim to fix a problem with an account or on your PC. Obviously, a phishing page is bad enough, but the malware deposited by this upgraded hack lets bad actors spy on you in addition to potentially stealing a Microsoft 365 account. And most people rarely question hotel Wi-Fi with a captive portal login system. At a property that nice, you’ll likely assume other users are a threat, not the portal itself.

So what should you do to stay safe when on public Wi-Fi, whether fully open or kept behind a portal? Here are the four things I always recommend:

  1. Ensure you’re on the official public Wi-Fi network. Smart hackers will create networks that sound similar to legitimate ones, hoping to catch people who aren’t paying close attention. For example, just the other day, I saw an “XfinityWifi” hotspot available in a location that seemed unusual.
  2. If you’re routed through a portal, pay attention to the instructions. Most will ask you to agree to terms before proceeding. Hotel portals may ask for your surname and your room number. No legitimate portal will tell you to run commands on your device, or input your login information for an account. (Especially an unrelated account.)
  3. Once connected, use a VPN. This sets up an encrypted tunnel, where all your web traffic routes through a secure server. If someone also on the same public Wi-Fi network as you tries to snoop on your activity, they will only see that you’re connecting to the VPN service. (Obviously, this method is only as good as the VPN you choose, so pick one that has strong security, plus a verified no-logs policy to maintain your privacy.)
  4. If you can’t use a VPN, avoid browsing insecure websites—anything that only has HTTP (no S) in the address. Such sites are not encrypted, meaning that anyone else on that public Wi-Fi network can see the exact data passed back and forth between your device and that insecure website. Also consider avoiding use of sensitive apps and websites (e.g., financial).

Of course, the easiest way to stay safe on public Wi-Fi is to just not use it. Cell phone connections are harder to hack—so keep using the data on your phone. If you need a connection for your PC, turn on your phone’s hotspot. If you have enough data on your plan, this solution requires the least amount of effort.

In the news

Hackers of all stripes stayed busy this week. On one side, Def Con attendees showed off their skills at this year’s annual hacking and cybersecurity conference. (Also allegedly outside of it, too.) On the other, bad actors breached multiple companies, with a couple smaller leaks affecting consumers directly. A third data leak is huge and its impact remains to be seen.

USB-C port
Even now, insecure USB devices can end up compromising your PC.

Pexels: Karolina Grabowska

The bad

  • A European distributor of Steam Machines was hacked, prompting Valve to alert buyers that their names, addresses, phone numbers, email addresses, and order information may have been leaked. Those affected should screen emails, texts, and phone calls carefully for potential scam attempts.

  • Modular PC maker Framework also experienced a similar breach with names, email addresses, physical addresses, and phone numbers for “all customers” stolen. The leak was a result of a hack on partner Metabase, a business intelligence service.

  • On a dramatically larger scale: Two security firms say “millions of secrets” were stolen when an LLM dependency was hacked in March. Just 40 minutes leaked credentials for major companies such as Nvidia, Amazon, Samsung, Airbus, FedEx, Volkswagen, X/Twitter, Epic Games, and HP. As consumers, this hasn’t hit us directly… yet. These days, supply chain attacks like this often have trickle-down effects.

The old-school

  • Hackers still love USB-based exploits—at cybersecurity conference Def Con 34, researchers demonstrated using Windows’ Plug and Play feature to install compromised vendor software and gain system-level privileges. It’s a strong reminder to keep unverified USB devices away from your PC.

  • Def Con attendees also allegedly demonstrated their taste for mayhem while aboard a Delta flight, jamming the on-board Wi-Fi and setting up a fake network. Hackers always gonna hack, it seems.

The ongoing

  • The feud between Microsoft and security researcher Nightmare Eclipse rages on—the latter has disclosed yet another zero-day vulnerability in Windows, this time affecting Microsoft Defender. Called ShieldBreak, the exploit allows a hacker to gain system-level privileges on Windows 10 and 11 PCs. No fix is available yet.

Tip of the week

Duolingo data leak on hacker forum
Duolingo’s 2023 data leak is one reason why I use a random name in that app.

Bleeping Computer

Here’s a quick way to preserve your privacy: You don’t have to give your real name to most apps and services. Use Duolingo for free? Got peer pressured into signing up for MyFitnessPal? Go incognito with a random pseudonym.

The only exception: Important services where you must undergo identity verification or would need to use identity verification to recover the account. (Most obvious example: bank accounts.) Your real name may also be necessary when you must keep a payment method on file or have items shipped to you.

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.