In a fresh development, this doesn't affect our editorial independence. When you purchase through links in our articles, we may earn a small commission.

According to the latest update, but you shouldn’t–at least not completely and not without any safeguards. You probably trust public Wi-Fi.

In a fresh development, as detailed by Microsoft, hackers have been infiltrating login portals at hotels. Previously, such hijacking was used to redirect users to fake Microsoft 365 login pages or subvert Microsoft’s corporate-grade authentication method (Entra ID). But now there’s a more dangerous variation that tricks people into installing malware. A fresh kind of attack is the most recent reminder of this.

According to the latest update, want this newsletter to come directly to your inbox? Sign up on our website! Welcome to Safe Mode, your weekly report for pressing security and privacy news—and what steps to take next.

In a fresh development, obviously, a phishing page is bad enough, but the malware deposited by this upgraded hack lets bad actors spy on you in addition to potentially stealing a Microsoft 365 account. And most people rarely question hotel Wi-Fi with a captive portal login system. At a property that nice, you’ll likely assume other users are a threat, not the portal itself. It relies on a technique called ClickFix, where a popup appears with instructions that claim to fix a problem with an account or on your PC.

The report highlights that here are the four things I always recommend:. So what should you do to stay safe when on public Wi-Fi, whether fully open or kept behind a portal?

In a fresh development, cell phone connections are harder to hack—so keep using the data on your phone. If you need a connection for your PC, turn on your phone’s hotspot. If you have enough data on your plan, this solution requires the least amount of effort. Of course, the easiest way to stay safe on public Wi-Fi is to just not use it.

The report highlights that on one side, Def Con attendees showed off their skills at this year’s annual hacking and cybersecurity conference. (Also allegedly outside of it, too.) On the other, bad actors breached multiple firms, with a couple smaller leaks affecting consumers directly. A third data leak is huge and its impact remains to be seen. Hackers of all stripes stayed busy this week.

As part of the ongoing story, use Duolingo for free? Got peer pressured into signing up for MyFitnessPal? Go incognito with a random pseudonym. Here’s a quick way to preserve your privacy: You don’t have to give your real name to most apps and services.

Industry observers note that (Most obvious example: bank accounts.) Your real name may also be necessary when you must keep a payment method on file or have items shipped to you. The only exception: Important services where you must undergo identity verification or would need to use identity verification to recover the account.

According to the latest update, since joining the team in 2016, she’s written about CPUs, Windows, PC building, Chrome, Raspberry Pi, and much more—while also serving as PCWorld’s resident bargain hunter (#slickdeals). Currently her focus is on security, helping people understand how best to protect themselves online. Her work has previously appeared in PC Gamer, IGN, Maximum PC, and Official Xbox Magazine. A 15-year veteran of technology and video platform releases journalism, Alaina Yee covers a variety of topics for PCWorld.