:

220M TRAVELER RECORDS EXPOSED IN VIETNAM APIS LEAK

DEV DESK1 MIN READ
TUE, SEP 8, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

An unsecured Advance Passenger Information System (APIS) database exposed 220 million passenger and crew records. Researchers accessed the Vietnam-linked system through default cloud credentials, revealing sensitive data spanning nearly a decade.

The exposed database contained names, passport numbers, dates of birth, nationalities, and flight details for records dating from 2017 to 2026. Researchers discovered the breach through a cloud-based access path secured only by default login credentials, highlighting a critical security gap in the travel infrastructure. APIS databases store passenger information submitted to aviation authorities ahead of flights. The scale of this exposure affects travelers globally and raises concerns about the security protocols protecting sensitive travel data. The Vietnam connection suggests the database belonged to or was linked to Vietnamese aviation operations. The breach underscores persistent vulnerabilities in systems handling high-volume personal data, particularly when default authentication mechanisms remain unchanged in production environments. No information has been provided regarding notification of affected parties or remediation efforts.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Google is accelerating Chrome's release cycle to every two weeks, moving faster to deploy security patches and new features as artificial intelligence reshapes the threat landscape.

JUST NOWAI Desk

Bluetooth jammers might seem like a solution to neighborhood noise, but they carry serious legal penalties. Using one violates federal communications law regardless of your intent.

1H AGOIndustry Desk

Adobe released an emergency fix for CVE-2026-75650, a maximum-severity zero-day vulnerability actively exploited in the wild. The flaw, dubbed StyleSmuggler, affects multiple versions of Magento and Adobe Commerce.

1H AGOSecurity Desk

SAP has released security updates addressing 20 vulnerabilities across its product portfolio, including a maximum-severity memory corruption bug in SAP Kernel code designated OVERPASS.

1H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.