Visualização normal

Hoje — 9 de Setembro de 2026Security Affairs
  • ✇Security Affairs
  • Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data Pierluigi Paganini
    An exposed Vietnam-linked APIS database contained 220.8 million passenger and crew records, including passport and flight data. Researchers found an exposed Advance Passenger Information System (APIS) database containing 220.8 million passenger and crew records from January 2017 to April 2026. The data includes sensitive details such as passport numbers, identities and flight information, potentially affecting travelers of many nationalities who flew to, from or through Vietnam. Kinryū L
     

Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data

8 de Setembro de 2026, 08:01

An exposed Vietnam-linked APIS database contained 220.8 million passenger and crew records, including passport and flight data.

Researchers found an exposed Advance Passenger Information System (APIS) database containing 220.8 million passenger and crew records from January 2017 to April 2026.

The data includes sensitive details such as passport numbers, identities and flight information, potentially affecting travelers of many nationalities who flew to, from or through Vietnam. Kinryū Labs discovered the Elasticsearch cluster, named “pax-info,” while searching for exposed databases.

It contained 29 indices and about 107 GB of data. The researchers linked the server to IP space assigned to Viettel in Hanoi, but could not confirm which Vietnamese organization operated it.

Researchers found an exposed APIS database linked to Vietnam that contained more than 220 million passenger and crew records from 2017 to 2026. The data included passport numbers, identities and flight details. The Elasticsearch database, discovered by Kinryū Labs, held about 107 GB of data across 29 indices. It was hosted on IP addresses assigned to Viettel in Hanoi, although researchers could not confirm which Vietnamese organization operated the system.

The exposed database contained names, dates of birth, sex, nationalities, passport or travel-document numbers, expiration dates and issuing countries, BleepingComputers reports.

It also included flight numbers and dates, airlines, departure and destination airports, transit airports, seat numbers, baggage references, and scheduled, estimated and actual flight times. The database covered many airlines across Asia-Pacific, Europe and the Middle East, so it could affect people from around the world who traveled to or through Vietnam between 2017 and 2026.

Kinryū Labs confirmed the data was real by matching records with its researchers’ own trips to Vietnam. The total also counts travel records, not unique people, so frequent travelers may appear multiple times.

While the researchers could not provide a complete breakdown by nationality, the data covered numerous international airlines across Asia-Pacific, Europe, and the Middle East. As a result, the exposed records could relate to people from virtually anywhere who visited or transited through Vietnam over the nine-year period.

Kinryū Labs verified that the information was legitimate by matching records in the database against its researchers’ own travel to Vietnam.

The figures represent travel records rather than unique individuals. Passengers and crew members who flew multiple times may therefore appear repeatedly in the database.

Kinryū Labs reached the exposed database by combining two security misconfigurations. Direct internet access returned a 401 error, but another cloud-based path exposed the cluster and accepted default credentials.

FOFA first detected the host in 2022 and identified it as a database in 2023, but researchers could not determine when the passenger data became accessible. The records cover more than nine years, but the actual exposure period remains unknown.

Kinryū Labs reported the issue to Vietnamese authorities, affected airlines and national CERTs on June 3. The database was secured by June 8, with Singapore Airlines helping coordinate the response.

Researchers found no evidence that the listed airlines operated the system or suffered a network breach. They also found no ransom notes or signs that attackers had altered the database.

However, without server logs, they could not determine whether anyone had copied or stolen the data before the system was secured.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, APIS)

Antes de ontemSecurity Affairs
  • ✇Security Affairs
  • Slovakia Warns of Cyber Risks in Road Speed Cameras Pierluigi Paganini
    Slovakia warns that vulnerable speed cameras could expose vehicle data, enable remote access and provide attackers with a foothold into public networks. Slovakia’s National Security Authority, NBÚ, recently issued a warning about several road speed cameras, calling them a significant cyber threat. The alert is not about someone deleting a speeding ticket. It is about connected devices that collect vehicle data, communicate with other systems, and may contain remote-access functions that the
     

Slovakia Warns of Cyber Risks in Road Speed Cameras

24 de Agosto de 2026, 05:52

Slovakia warns that vulnerable speed cameras could expose vehicle data, enable remote access and provide attackers with a foothold into public networks.

Slovakia’s National Security Authority, NBÚ, recently issued a warning about several road speed cameras, calling them a significant cyber threat. The alert is not about someone deleting a speeding ticket. It is about connected devices that collect vehicle data, communicate with other systems, and may contain remote-access functions that the operator cannot fully control.

The Slovak authority examined a sample of the NERO R-ONE camera system at the request of the Interior Ministry. It named three product lines in its warning: NERO R-ONE devices sold by Cyprus-based SODASUS, Cordon-series speed cameras made by Russia’s Simicon, and Cordon-series products sold by Croatia’s NEROline.

“The National Security Authority warns of a significant cyber threat associated with the use of several types of road speed cameras.” reads the alert. “A security analysis has identified several risks and recommends that affected entities identify the products in question in their infrastructure.”

The problems went beyond a simple configuration issue. NBÚ found differences between the documented and actual communication settings, uncertainty about where the hardware and software came from, software that did not match the declared version, and weak security protections.

“The security analysis identified several risks, including the true origin of the camera hardware and software, inconsistency between the documented and detected configuration of the product’s communication interfaces, and pre-configured remote access and product management mechanisms.” the agency wrote on LinkedIn.

That last point deserves attention. A road camera should be managed by the organisation that owns it, under controls that it can inspect, configure and audit. If a device includes pre-set remote-access or management mechanisms outside the customer’s full control, it creates a blind spot in a system that may sit on a public-sector network or communicate with other operational services.

Speed cameras do much more than take pictures and measure speed. They photograph vehicles, record timestamps, process licence-plate data, store evidence and send information to backend systems used by authorities. Depending on the setup, they may also connect to mobile networks, roadside equipment, police systems, municipal platforms or third-party maintenance services.

If attackers compromise a camera, they could access data, change or delete records, manipulate how it measures or reports violations, or shut it down. If the network lacks proper segmentation, they could also use the camera as a foothold to reach other systems. The camera may not be the real target. It could simply be the unlocked door.

The warning aims to alert essential-service operators and other organisations that these road cameras could pose a serious cybersecurity risk. In the wrong circumstances, attackers could use them to disrupt networks, systems or services.

The Slovak Interior Ministry reportedly took the equipment out of its pilot deployment while the matter was investigated. Public reporting also says the ministry asked the supplier to remove the units and replace them with equipment meeting Slovak and EU legal, technical and security requirements.

The Russian connection adds an obvious geopolitical dimension, but it should not become a substitute for technical analysis. NBÚ did not say that every device was actively spying on users or that the equipment contained a proven backdoor. Its warning is about identified security risks, limited operator control, uncertainty over hardware and software provenance, and remote-management mechanisms that could not be fully accounted for.

That is enough reason to take action. Security checks for connected public devices cannot rely only on the brand, the country listed on the invoice or the vendor’s claims. Operators should know exactly what software and firmware the device runs, how remote access works and who controls it. They should also use independent security testing, secure updates and network segmentation.

The same lesson applies beyond Slovakia. Smart cameras, licence-plate readers, parking sensors, environmental monitors, traffic lights and roadside communication systems are becoming part of public infrastructure. They are often cheap, easy to overlook and managed by public agencies, contractors and manufacturers. That makes them just as important to secure as other critical systems.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Speed Cameras)

  • ✇Security Affairs
  • One Railway Radio Outage Stopped Trains Across Germany and Nobody Knew Why Pierluigi Paganini
    A nationwide GSM-R outage stopped trains across Germany, exposing how one aging communications system can still bring an entire rail network to a halt At 10:30 PM on Tuesday June 23, Deutsche Bahn told passengers something that had never happened before for technical reasons: all trains across Germany were being held at their stations. The company confirmed the outage was caused by a nationwide failure of its GSM-R system, the Global System for Mobile Communication for Railways, which ha
     

One Railway Radio Outage Stopped Trains Across Germany and Nobody Knew Why

24 de Junho de 2026, 05:29

A nationwide GSM-R outage stopped trains across Germany, exposing how one aging communications system can still bring an entire rail network to a halt

At 10:30 PM on Tuesday June 23, Deutsche Bahn told passengers something that had never happened before for technical reasons: all trains across Germany were being held at their stations.

The company confirmed the outage was caused by a nationwide failure of its GSM-R system, the Global System for Mobile Communication for Railways, which handles internal communication across the entire rail network. Without that link, running trains safely isn’t possible, so nothing moved.

“All trains are suspended in Germany’s most populous state, North Rhine-Westphalia.” reported the German media outlet DW.

That line alone gives you the scale. Berlin’s public transport authorities confirmed that municipal, regional, and long-distance Deutsche Bahn trains were all affected. The Berlin S-Bahn suspended all trains on all lines. Stuttgart halted everything on its network.

Deutsche Bahn CEO Evelyn Palla spoke to Bild newspaper in the early hours and was candid about where things stood:

“We are now trying to get the trains into stations so that travelers can disembark. And then we have to fix the problem, which we don’t yet know.” Deutsche Bahn CEO Evelyn Palla said.

That quote is doing a lot of work. The head of one of Europe’s largest rail operators, publicly admitting she didn’t yet know what had broken her entire network.

Engineers identified the cause of the disruption within roughly ninety minutes of the first announcement, and the network came back online just before 1 a.m. Deutsche Bahn said technicians were working around the clock and later confirmed the fix was successful. The company apologized to passengers and said it would issue taxi and hotel vouchers to those affected, with replacement buses arranged where possible.

The Stuttgart S-Bahn’s statement to passengers during the outage captures exactly the kind of uncertainty that cascaded across every station in the country.

“At present, all S-Bahn trains across the entire network are being held at platforms.” said authorities in Stuttgart. “Please check your journey in the travel information system for alternative transport options. We will inform you as soon as we have new information and can assess how long the disruption will last.”

Which is the polite way of saying: we have no idea how long this will last.

GSM-R is a railway-specific version of 2G mobile technology, deployed across Europe since 2000 as the standard for voice and data communications between drivers and control centers. Deutsche Bahn has already signed with Nokia to replace it with a 5G system using the Future Railway Mobile Communication System standard. That replacement hasn’t arrived yet, which means the network that failed Tuesday night is still the one everything depends on. No evidence of a cyberattack or physical infrastructure damage has emerged. The exact technical cause of the failure has not been publicly disclosed. Deutsche Bahn is already notorious for frequent delays and cancellations. A complete nationwide technical halt, in calm weather, with no external cause, is a different category of problem from a late train.

At this time, the situation appears normal; however, as of 6:30 AM, DB warned “some isolated disruptions may still occur” and advised passengers they’ll need to check that their connections will run on time.

The Register confirmed that there is no evidence that the outage was caused by a cyberattack or by physical infrastructure damage such as cut cables. The incident nevertheless raises questions about resilience, as critical infrastructure networks are expected to include multiple layers of redundancy to prevent widespread disruptions. The organization praised its IT team, stating that its experts worked tirelessly and successfully restored services.

In August 2023, Poland’s Internal Security Agency (ABW) and national police launched an investigation into a hacking attack on the state’s railway network. According to the Polish Press Agency, the attack disrupted the traffic overnight.

Stanisław Zaryn, deputy coordinator of special services, told the news agency that Polish authorities were investigating the unauthorized usage of the system used to control rail traffic.

Since the beginning of the Russian invasion of Ukraine, Poland’s railway system has represented a crucial transit infrastructure for Western countries’ support of Ukraine.

Zaryn explained that the attacks are part of a broader activity conducted by Russia to destabilize Poland.

In April 2024, the Czech transport minister Martin Kupka warned that Russia conducted ‘thousands’ of attempts to sabotage European railways.

The Czech Republic’s transport minister told the Financial Times that the attacks aim to destabilize the EU and sabotage critical infrastructure.

Kupka confirmed that Russia-linked threat actors have conducted “thousands of attempts to weaken our systems” since the beginning of the Russian invasion of Ukraine.

The state-sponsored hackers also targeted signaling systems and networks of the Czech national railway operator České dráhy, Kupka said.

The Czech cyber defense was able to detect and neutralize these attacks; however, the minister highlighted that sabotaging railways could cause serious accidents.

At the end of October 2022, a cyberattack caused trains in Denmark to stop; it hit a third-party IT service provider. The attack hit the Danish company Supeo, which provides enterprise asset management solutions to railway companies, transportation infrastructure operators, and public passenger authorities.

DSB is the largest train operating company in Denmark.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

❌
❌