Researchers find SQL injection to bypass airport TSA security checks
ID: 8d782381-c31d-5914-9e04-f6a4012c45e9
STIX ID: report--8d782381-c31d-5914-9e04-f6a4012c45e9
Feed Name: Bleeping Computer
Threat Score
Security researchers discovered an SQL injection flaw in FlyCASS — a third-party system used for TSA Known Crewmember (KCM) and Cockpit Access Security System (CASS) management — that allowed adding fake crew members and could let attackers bypass screening and access aircraft cockpits; FlyCASS was disconnected and later fixed after disclosure, and the service also shows signs of a prior MedusaLocker ransomware incident.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
