Learn
active
220 million traveler records exposed via APIS default credentials
- Engineer — Learn: The root cause — default credentials left on a cloud-exposed system — is a textbook misconfiguration. No specific software or CVE is named, so there is no patch to apply; use this as a prompt to audit your own cloud services for default or uncycled credentials.
- SOC/IR — Skip
- Leader — Learn: A breach of this scale — spanning nearly a decade of passport and travel data — illustrates third-party government data custody risk. No direct vendor relationship action is needed for most organizations, but it is useful context for board-level discussions on supply-chain and sovereign data exposure.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.