Schneier on Security's Journal
 
[Most Recent Entries] [Calendar View]

Friday, August 1st, 2025

    Time Event
    3:31p
    Spying on People Through Airportr Luggage Delivery Service

    Airportr is a service that allows passengers to have their luggage picked up, checked, and delivered to their destinations. As you might expect, it’s used by wealthy or important people. So if the company’s website is insecure, you’d be able to spy on lots of wealthy or important people. And maybe even steal their luggage.

    Researchers at the firm CyberX9 found that simple bugs in Airportr’s website allowed them to access virtually all of those users’ personal information, including travel plans, or even gain administrator privileges that would have allowed a hacker to redirect or steal luggage in transit. Among even the small sample of user data that the researchers reviewed and shared with WIRED they found what appear to be the personal information and travel records of multiple government officials and diplomats from the UK, Switzerland, and the US.

    “Anyone would have been able to gain or might have gained absolute super-admin access to all the operations and data of this company,” says Himanshu Pathak, CyberX9’s founder and CEO. “The vulnerabilities resulted in complete confidential private information exposure of all airline customers in all countries who used the service of this company, including full control over all the bookings and baggage. Because once you are the super-admin of their most sensitive systems, you have have [sic] the ability to do anything.”

    11:34p
    Friday Squid Blogging: A Case of Squid Fossil Misidentification

    What scientists thought were squid fossils were actually arrow worms.

    << Previous Day 2025/08/01
    [Calendar]
    Next Day >>

Schneier on Security   About LJ.Rossia.org