As cited
Copy frozen at (site build).
threat intel
Scans Targeting Hospitality Applications
Scans targeting a legacy hospitality management system based on PBX in a Flash began on September 15, 2026, from a single IP address associated with a bulletproof hosting provider. The application contains multiple SQL injection vulnerabilities and lacks authentication or access controls, though it may be abandoned or experimental. The reconnaissance targets common administrative and hotel system paths, suggesting attackers are probing for entry points to compromise hotel infrastructure.
Why it matters: Hotel operators and security teams managing legacy PBX or hospitality systems should investigate whether this or similar applications are running in their environment, as they present a direct avenue for attackers to steal guest data, execute man-in-the-middle attacks, or impersonate internal callers.
- Source published
- First seen by Cybersecurity Tracker