Academic researchers successfully demonstrated a method to compromise systems on a Boeing 737 using a concealed, coin-sized hardware device. This device, when attached to an external port, grants malicious actors remote access to the aircraft's systems. While safety systems are expected to prevent direct physical harm, an attacker could spoof critical data such as air temperature readings and aircraft weight.
The demonstrated vulnerability extends beyond data spoofing, potentially allowing an attacker to change a plane's flight plan and divert it from its intended route. This highlights a significant security concern for aviation, emphasizing the need for robust physical and digital security measures for aircraft systems.
LexisNexis recently took its Diligence, Metabase API, and Newsdesk services offline after detecting unusual activity on servers managed by a third-party vendor. The company disconnected these systems to contain the potential threat. LexisNexis clarified that its Metabase API product is distinct from Metabase Cloud, which recently disclosed a zero-day vulnerability.
This incident marks a potential third data breach for LexisNexis, raising concerns about the company's cybersecurity posture and its reliance on third-party vendors. The investigation is ongoing to determine the nature and extent of the unusual activity.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Academic researchers demonstrated how a small hardware device could compromise Boeing 737 systems, potentially allowing data spoofing and flight plan alteration. Separately, LexisNexis took several services offline to investigate unusual activity, marking a potential third data breach for the company.