Microsoft Security Blog · April 7, 2026

SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks

Why it matters

Forest Blizzard has been compromising insecure routers and small-office devices, turning them into infrastructure for adversary-in-the-middle attacks.

My takeaway: Useful for infrastructure threat modeling. AI systems often depend on distributed home-office and edge environments, so weak routing and DNS controls can still undercut otherwise strong cloud-side security.