Tag Archive for: 1.5M

Hacking Forum Exposes Entire US No Fly List Of Over 1.5M Names As TSA Investigates


hero hacking forum exposes us no fly list tsa investigates news
Earlier this month, a Swiss hacker who goes by the name maia arson crimew exfiltrated a copy the US government’s No Fly List from an insecure server. This list, which names individuals who are forbidden from flying anywhere within US borders, is a subset of the Terrorist Screening Database and is kept hidden from the public. However, this list is now publicly available after an unknown actor posted the version accessed by crimew to BreachForums.

Crimew originally came into possession of this list when browsing the Jenkins servers on ZoomEye, which, similar to Shodan, lets users search for servers connected to the internet. The hacker happened to come across a Jenkins server operated by the airline CommuteAir. After digging through this server for a time, crimew discovered credentials for the company’s Amazon Web Services (AWS) infrastructure. The hacker then used the credentials to connect to this infrastructure, which crimew found to contain a 2019 copy of the No Fly List, as well as a “selectee” list. This second list likely names all those who are subject to Secondary Security Screening Selection (SSSS).

In a blog post published by crimew, the hacker acknowledges that these lists are sensitive in nature before stating, “[I] believe it is in the public interest for this list to be made available to journalists and human rights organizations.” Crimew accordingly made the lists available for access upon request, requiring that applicants be journalists, researchers, or other parties with legitimate interest. The service hosting the lists, Distributed Denial of Secrets, further states that requests will probably be rejected if interested individuals don’t provide sufficient information to verify their identities and if said individuals are “hacktivist[s] that want to exploit the data” or “researcher[s] without a clear journalist or academic project.”

breach forums post tsa no fly list
BreachForums post sharing the No Fly List (click to enlarge)

Despite the apparent limitations on who can access this information, someone managed to obtain a copy of the lists and posted them for free on BreachForums. According to BleepingComputer, the No Fly List contains 1,566,062 entries and the…

Source…

Selfie Android Apps with 1.5M+ Installs Push Ads, Can Record Audio – BleepingComputer

  1. Selfie Android Apps with 1.5M+ Installs Push Ads, Can Record Audio  BleepingComputer
  2. iOS 13 vs. Android 10: Which is more secure?  CNET
  3. Two Android adware apps with 1.5 million downloads removed from Google Play Store  ZDNet
  4. Android VPN apps found serving disruptive ads  TechRadar
  5. View full coverage on read more

“android security news” – read more

Neiman Marcus to Pay $1.5M to End Data Breach Probe | New Jersey Law Journal – Law.com

  1. Neiman Marcus to Pay $ 1.5M to End Data Breach Probe | New Jersey Law Journal  Law.com
  2. Neiman Marcus reaches $ 1.5 million data breach settlement  Chicago Tribune
  3. Neiman Marcus Pays $ 1.5M For 2013 Data Breach  Annapolis, MD Patch
  4. Settlement reached in Neiman Marcus data breach that affected 65,644 Texans  Star-Telegram
  5. Neiman Marcus pays $ 1.5 million to Texas, 42 other states over 2013 data breach  Dallas News
  6. View full coverage on read more

“data breach” – read more