Hotel Beacon NYC
Welcome to the Hotel Beacon on linkedIn! A place for current and past employees to connect and remain current on what is happening at the hotel.

Welcome to the Hotel Beacon on linkedIn! A place for current and past employees to connect and remain current on what is happening at the hotel.

An IHG hotel. IHG Hotels & Resorts [LON:IHG, NYSE:IHG (ADRs)] is a global hospitality company, with a purpose to provide True Hospitality for Good. At Holiday Inn Express, we strive to make every interaction you have with us simple, smart and refreshingly engaging. With over 3,000 hotels in 75 different countries, Holiday Inn Express is IHG’s largest brand and one of the fastest growing hotel brands in the industry. Holiday Inn Express offers affordable hotels, high speed internet access, free breakfast and a comfortable room that will leave you relaxed and recharged. InterContinental Hotels Group PLC is the Group’s holding company and is incorporated in Great Britain and registered in England and Wales. Approximately 350,000 people work across IHG's hotels and corporate offices globally. Visit https://www.ihg.com/holidayinnexpress/hotels/us/en/reservation for hotel information and reservations and www.ihgrewards.com for more on IHG One Rewards. For our latest news, follow us on LinkedIn, Facebook, Instagram, TikTok and Twitter.
Security & Compliance Standards Overview












No incidents recorded for Hotel Beacon NYC in 2026.
No incidents recorded for Holiday Inn Express in 2026.
Hotel Beacon NYC cyber incidents detection timeline including parent company and subsidiaries
Holiday Inn Express cyber incidents detection timeline including parent company and subsidiaries
Last 3 Security & Risk Events by Company
Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the login error view template `login.twig` of versions 2.19.1 and below. The `username` value can be echoed back without proper contextual encoding when authentication fails. An attacker can execute script in the login page context. This issue has been fixed in version 2.19.2.
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the DomainCheckerApp class within domain/script.js of Sourcecodester Domain Availability Checker v1.0. The vulnerability occurs because the application improperly handles user-supplied data in the createResultElement method by using the unsafe innerHTML property to render domain search results.
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension during the save process. This allows an unauthenticated attacker to upload arbitrary PHP code by spoofing the MIME type as an image, leading to full system compromise.
A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host user with write access to the pre-created jailer directories to overwrite arbitrary host files via a symlink attack during the initialization copy at jailer startup, if the jailer is executed with root privileges. To mitigate this issue, users should upgrade to version v1.13.2 or 1.14.1 or above.
An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform thru 2025-05-28. This unauthenticated endpoint returns a list of cashier accounts, including names, email addresses, usernames, and passwords hashed using MD5. As MD5 is a broken cryptographic function, the hashes can be easily reversed using public tools, exposing user credentials in plaintext. This allows remote attackers to perform unauthorized logins and potentially gain access to sensitive POS operations or backend functions.