CuraSec

Learn active

220 million traveler records exposed via APIS default credentials

2026-09-08 15:04 UTC · BleepingComputer · read the source ↗ #data-breach#pii-exposure#default-credentials
  • Engineer — Learn: The root cause — default credentials left on a cloud-exposed system — is a textbook misconfiguration. No specific software or CVE is named, so there is no patch to apply; use this as a prompt to audit your own cloud services for default or uncycled credentials.
  • SOC/IR — Skip
  • Leader — Learn: A breach of this scale — spanning nearly a decade of passport and travel data — illustrates third-party government data custody risk. No direct vendor relationship action is needed for most organizations, but it is useful context for board-level discussions on supply-chain and sovereign data exposure.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.