Connect with us

Published

on

Over the years, travelers have repeatedly been warned to avoid public Wi-Fi in places like airports and coffee shops. Airport Wi-Fi, in particular, is known to be a hacker honeypot, due to what is typically relatively lax security. But even though many people know they should stay away from free Wi-Fi, it proves as irresistible to travelers as it is to hackers, who are now updating an old cybercrime tactic to take advantage.

An arrest in Australia over the summer set off alarm bells in the United States that cybercriminals are finding new ways to profit from what are called “evil twin” attacks. Also classified within a type of cybercrime called “Man in the Middle” attacks, evil twinning occurs when a hacker or hacking group sets up a fake Wi-Fi network, most often in public settings where many users can be expected to connect.

In this instance, an Australian man was charged with conducting a Wi-Fi attack on domestic flights and airports in Perth, Melbourne, and Adelaide. He allegedly set up a fake Wi-Fi network to steal email or social media credentials.

“As the general population becomes more accustomed to free Wi-Fi everywhere, you can expect evil twinning attacks to become more common,” said Matt Radolec, vice president of incident response and cloud operations at data security firm Varonis, adding that no one reads the terms and conditions or checks the URLs on free Wi-Fi.

“It’s almost a game to see how fast you can click “accept” and then ‘sign in’ or ‘connect.’ This is the ploy, especially when visiting a new location; a user might not even know what a legitimate site should look like when presented with a fake site,” Radolec said.

Today’s ‘evil twins’ can more easily hide

One of the dangers of today’s twinning attacks is that the technology is much easier to disguise. An evil twin can be a tiny device and can be tucked behind a display in a coffee shop, and the small device can have a significant impact.

“A device like this can serve up a compelling copy of a valid login page, which could invite unwary device users to enter their username and password, which would then be collected for future exploitation,” said Cincinnati-based IT consultant Brian Alcorn. 

The site doesn’t even have to actually log you in. “Once you’ve entered your information, the deed is done,” Alcorn said, adding that a harried, weary traveler probably would just think the airport Wi-Fi is having issues and not give it another thought.  

People who are not careful with passwords, such as use of pet’s names or favorite sports teams as their password for everything, are even more vulnerable to an evil twin attack. Alcorn says for individuals who reuse username and password combinations online, once the credentials are obtained they can be fed into AI, where its power can quickly give cybercriminals the key.

“You are susceptible to exploitation by someone with less than $500 in equipment and less skill than you might imagine,” Alcorn said. “The attacker just has to be motivated with basic IT skills.”

How to avoid becoming a victim of this cybercrime

When in public places, experts say it’s best to use alternatives to public WiFi networks.

“My favorite way to avoid evil twin attacks is to use your phone’s mobile hotspot if possible,” said Brian Callahan, Director of the Rensselaer Cybersecurity Collaboratory at Rensselaer Polytechnic Institute.

Users would be able to spot an attack if through a phone relying on its mobile data and sharing it via a mobile hotspot.

“You will know the name of that network since you made it, and you can put a strong password that only you know on it to connect,” Callahan said.

If a hotspot isn’t an option, a VPN can also provide some protection, Callahan said, as traffic should be encrypted to and from the VPN.

“So even if someone else can see the data, they can’t do anything about it,” he said.

Airport, airline internet security issues

At many airports, the responsibility for WiFi is outsourced and the airport itself has little if any involvement in safeguarding it. At Dallas Fort Worth International Airport, for example, Boingo is the Wi-Fi provider.

“The airport’s IT team does not have access to their systems, nor can we see usage and dashboards,” For said an airport spokesman. “The network is isolated from DAL’s systems as it is a separate standalone system with no direct connection to any of the City of Dallas’ networks or systems internally.” 

A spokeswoman for Boingo, which provides service to approximately 60 airports in North America, said it can identify rogue Wi-Fi access points through its network management. “The best way passengers can be protected is by using Passpoint, which uses encryption to automatically connect users to authenticated Wi-Fi for a safe online experience,” she said, adding that Boingo has offered Passpoint since 2012 to enhance Wi-Fi security and eliminate the risk of connecting to malicious hotspots.

Alcorn says evil twin attacks are “definitely” occurring with regularity in the United States, it’s just rare for someone to get caught because they are such stealth attacks.  And sometimes hackers use these attacks as a learning model. “Many evil twin attacks may be experimental by individuals with novice-to-intermediate skills just to see if they can do it and get away with it, even if they don’t use the collected information right away,” he said.

The surprise in Australia wasn’t the evil twinning attack itself, but the arrest.

“This incident isn’t unique, but it is unusual that the suspect was arrested,” said Aaron Walton, threat analyst at Expel, a managed services security company. “Generally, airlines are not equipped and prepared to handle or mediate hacking accusations. The typical lack of arrests and punitive action should motivate travelers to exercise caution with their own data, knowing what a tempting and usually unguarded -target it is — especially at the airport.”

In the Australian case, according to Australian Federal Police, dozens of people had their credentials stolen.

According to a press release from the AFP, “When people tried to connect their devices to the free WiFi networks, they were taken to a fake webpage requiring them to sign in using their email or social media logins. Those details were then allegedly saved to the man’s devices.”  

Once those credentials were harvested, they could be used to extract more information from the victims, including bank account information.

For hackers to be successful, they don’t have to dupe everyone. If they can persuade only a handful of people – statistically easy to do when thousands of harried and hurried people are milling around an airport – they will succeed.

“We expect WI-Fi to be everywhere. When you go to a hotel, or an airport, or a coffee shop, or even just out and about, we expect there to be Wi-Fi and often freely available WI-FI,” Callahan said. “After all, what’s yet another network name in the long list when you’re at an airport? An attacker doesn’t need everyone to connect to their evil twin, only some people who go on to put credentials into websites that can be stolen.”

The next time you’re at the airport, the only way to be 100% sure you’re safe is to bring your own Wi-Fi.

Continue Reading

Technology

Amazon faces FAA probe after delivery drone snaps internet cable in Texas

Published

on

By

Amazon faces FAA probe after delivery drone snaps internet cable in Texas

Amazon’s new MK30 Prime Air drone is displayed during Amazon’s “Delivering the Future” event at the company’s BFI1 Fulfillment Center, Robotics Research and Development Hub in Sumner, Washington on Oct. 18, 2023.

Jason Redmond | AFP | Getty Images

Amazon is facing a federal probe after one of its delivery drones downed an internet cable in central Texas last week.

The probe comes as Amazon vies to expand drone deliveries to more pockets of the U.S., more than a decade after it first conceived the aerial distribution program, and faces stiffer competition from Walmart, which has also begun drone deliveries.

The incident occurred on Nov. 18 around 12:45 p.m. Central in Waco, Texas. After dropping off a package, one of Amazon’s MK30 drones was ascending out of a customer’s yard when one of its six propellers got tangled in a nearby internet cable, according to a video of the incident viewed and verified by CNBC.

The video shows the Amazon drone shearing the wire line. The drone’s motor then appeared to shut off and the aircraft landed itself, with its propellers windmilling slightly on the way down, the video shows. The drone appeared to remain in tact beyond some damage to one of its propellers.

The Federal Aviation Administration is investigating the incident, a spokesperson confirmed. The National Transportation Safety Board said the agency is aware of the incident but has not opened a probe into the matter.

Amazon confirmed the incident to CNBC, saying that after clipping the internet cable, the drone performed a “safe contingent landing,” referring to the process that allows its drones to land safely in unexpected conditions.

“There were no injuries or widespread internet service outages. We’ve paid for the cable line’s repair for the customer and have apologized for the inconvenience this caused them,” an Amazon spokesperson told CNBC, noting that the drone had completed its package delivery.

Amazon delivery drone snaps internet cable in Texas

The incident comes after federal investigators last month opened a separate probe into a crash involving two of Amazon’s Prime Air drones in Arizona. The two aircrafts collided with a construction crane in Tolleson, a city west of Phoenix, prompting Amazon to temporarily halt drone deliveries in the area.

For over a decade, Amazon has been working to realize founder Jeff Bezos’ vision of drones whizzing toothpaste, books and other goods to customers’ doorsteps in 30 minutes or less. The company began drone deliveries in 2022 in College Station, Texas, and Lockeford, California.

But progress has been slowed by a mix of regulatory hurdles, missed deadlines and layoffs in 2023 that coincided with broader cost-cutting efforts by Amazon CEO Andy Jassy.

The company has previously said its goal is to deliver 500 million packages by drone per year by the end of the decade.

The hexacopter-shaped MK30, the latest generation of Amazon’s Prime Air drone, is meant to be quieter, smaller and lighter than previous versions.

Amazon says the drones are equipped with a sense-and-avoid system that enables them to “detect and stay away from obstacles in the air and on the ground.” The company recommends that customers maintain “about 10 feet of open space” on their property so drones can complete deliveries

The company began drone deliveries in Waco earlier this month for customers within a certain radius of its same-day delivery site who order eligible items weighing 5 pounds or less. The drone deliveries are supposed to drop packages off in under an hour.

Amazon has brought other locations online in recent months, including Kansas City, Missouri, Pontiac, Michigan, San Antonio, Texas, and Ruskin, Florida. Amazon has also announced plans to expand drone deliveries to Richardson, Texas.

Walmart began offering drone deliveries in 2021, and currently partners with Alphabet’s Wing and venture-backed startup Zipline to make drone deliveries in a number of states, including in Texas.

WATCH: Amazon unveils satellite terminal for enterprise customers — but Starlink still dominates

Amazon unveils satellite terminal for enterprise customers — but Starlink still dominates

Continue Reading

Technology

CNBC Daily Open: Nvidia’s crown looks increasingly uneasy on its head

Published

on

By

CNBC Daily Open: Nvidia's crown looks increasingly uneasy on its head

Jensen Huang, chief executive officer of Nvidia Corp., during the Taiwan Semiconductor Manufacturing Co. (TSMC) sports day event in Hsinchu, Taiwan, on Saturday, Nov. 8, 2025.

Lam Yik Fei | Bloomberg | Getty Images

Uneasy lies the head that wears the crown.

Shares of artificial intelligence czar Nvidia fell 2.6% on Tuesday as signs of unrest continued rippling through its kingdom.

Over the month, Nvidia has been contending with concerns over lofty valuations and an argument from the “The Big Short” investor Michael Burry that companies may be overestimating the lifespan of Nvidia’s chips. That accounting choice inflates profits, he alleged.

The pressure intensified last week in the form of a potential challenger to the crown. Google on Nov. 18 announced the release of its new AI model Gemini 3 — so far so good, given that Nvidia isn’t in the business of designing large language models  — powered by its in-house AI chips — uhoh.

And on Monday stateside, Meta, a potential kingmaker, appeared to signal that it is considering not just leasing Google’s custom AI chips, but also using them for its own data centers. It seemed like Nvidia felt the need to address some of those rumblings.

The chipmaker said on the social media platform X that its technology is more powerful and versatile than other types of AI chips, including the so-called ASIC chips, such as Google’s TPUs. Separately, Nvidia issued a private memo to Wall Street that disputed Burry’s allegations.

Power, whether in politics or semiconductors, requires a delicate balance.

Remaining silent may shroud those in power in a cloak of untouchability, projecting confidence in their authority — but also aloofness. Deigning to address unrest can soothe uncertainty, but also, paradoxically, signal insecurity.

For now, the crown is Nvidia’s to wear — and the weight of it is, too.

What you need to know today

And finally…

Lights on in skyscrapers and commercial buildings on the skyline of the City of London, UK, on Tuesday, Nov. 18, 2025. U.K. business chiefs urged Chancellor of the Exchequer Rachel Reeves to ease energy costs and avoid raising the tax burden on corporate Britain as she prepares this year’s budget.

Bloomberg | Bloomberg | Getty Images

The UK’s Autumn Budget is coming

The run-up to this year’s U.K. Autumn Budget has been different from the norm because so many different tax proposals have been floated, flagged, leaked and retracted in the weeks and months leading up to Wednesday’s statement.

It has also made it harder to gauge what we’re actually going to get when Finance Minister Rachel Reeves finally unveils her spending and taxation plans for the year ahead.

— Holly Ellyatt

Continue Reading

Technology

Workday stock slips on light quarterly margin guidance

Published

on

By

Workday stock slips on light quarterly margin guidance

Workday CEO Carl Eschenbach, right, walks to the morning session during the Allen & Co. Media and Technology Conference in Sun Valley, Idaho, on July 11, 2025.

David Paul Morris | Bloomberg | Getty Images

Workday shares slid more than 5% in extended trading Tuesday after the finance and human resources software maker issued quarterly margin guidance that came in below Wall Street projections.

Here’s how the company did in comparison with LSEG consensus:

  • Earnings per share: $2.32 adjusted vs. $2.18 expected
  • Revenue: $2.43 billion vs. $2.42 billion expected

The company forecast a fourth-quarter adjusted operating margin of at least 28.5% and $2.355 billion in subscription revenue, according to a statement. The StreetAccount consensus was a 28.7% margin and $2.35 billion in subscription revenue.

Workday’s revenue grew about 13% year over year in the quarter, which ended on Oct. 31. Net income of $252 million, or 94 cents per share, was up from $193 million, or 72 cents per share, in the same quarter a year ago.

Subscription revenue in the third quarter totaled $2.24 billion, with an adjusted operating margin of 28.5%. Analysts polled by StreetAccount had anticipated $2.24 billion in subscription revenue and a 28.1% margin.

During the fiscal third quarter, Workday announced artificial intelligence agents for analyzing employee performance testing financial health, and the company revealed plans to buy AI and learning software startup Sana for $1.1 billion. Also, activist investor Elliott Management said it had built a Workday stake worth over $2 billion.

Workday has seen its stock decline this year as pundits discuss the risk of generative AI tools threatening the growth prospects for cloud software incumbents. Company shares have fallen 9% so far in 2025, while the Nasdaq Composite index has gained 19%.

WATCH: Workday CEO Carl Eschenbach: There’s a narrative that AI is eating into software, that is false

Workday CEO Carl Eschenbach: There's a narrative that AI is eating into software, that is false

Continue Reading

Trending