logo

Tired of airport security queues? SQL inject yourself into the cockpit, claim researchers

ID: 12cea065-197d-5bec-962a-fa5750bd9f0b

STIX ID: report--12cea065-197d-5bec-962a-fa5750bd9f0b

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-08-30

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Security researchers discovered a SQL injection flaw in the FlyCASS third‑party system used for Known Crewmember (KCM) and Cockpit Access Security System (CASS) verification, which allowed authenticated admin access and the ability to add unauthorized crew entries—potentially enabling bypass of airport security checkpoints and cockpit jumpseat access; FlyCASS was subsequently disconnected from the programs. The report also highlights a possible L54/Medusa-derived ransomware infection observed on FlyCASS, raising additional operational and data-security concerns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.