Scammers posing as hotel staff are calling travelers to request urgent payment, exploiting reservation systems to gain credibility. The fraud targets both customers and businesses.
In 'reservation hijacking' scams, fraudsters contact guests claiming to be hotel employees requesting immediate payment to confirm bookings. These calls appear legitimate because scammers have accessed reservation systems or used caller ID spoofing.
Protection steps:
- Verify caller identity by hanging up and calling the hotel directly using the number on your booking confirmation
- Never provide payment details over the phone to unsolicited callers
- Be skeptical of urgent payment demands or requests for wire transfers
- Check your booking confirmation email for official contact methods
- Report suspicious calls to the hotel and relevant authorities
Hotels recommend guests use only official channels for payment modifications. Legitimate reservations are confirmed before arrival, and hotels rarely request emergency payments via unsolicited calls. Travelers should assume any unexpected payment request is fraudulent until verified through official channels.
WordPress disclosed an unauthenticated path traversal vulnerability that could lead to conditional remote code execution. The issue affects WordPress core and has been documented in an official security advisory.
Security researchers have demonstrated an attack allowing hackers with privileged access to register fake MFA providers and harvest user passwords during login. The vulnerability exploits the authentication process itself.
GrapheneOS, a privacy-focused Android fork, is on track to ship preinstalled on commercial devices within three years. The project has gained significant momentum in developer circles.
A Chinese-speaking threat actor has exploited vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to compromise 996 devices and steal over 18,500 database records from government systems.