Bangkok Airlines Admits Attackers Stole Passenger Data
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-13379 | Unauthenticated Path Traversal in Fortinet FortiOS SSL VPN CVE-2018-13379 is a path traversal flaw (CWE-22) in the Fortinet FortiOS SSL VPN web portal that allows an unauthenticated attacker to download FortiOS system files via specially crafted HTTP resource requests. By traversing directories through crafted requests to the exposed web portal, the attacker can retrieve sensitive files, a technique publicly documented as yielding the SSL VPN session file containing usernames and passwords in plaintext. Any organization running the SSL VPN web portal on a FortiGate appliance is affected, and risk is highest where the portal is directly reachable from the internet. The flaw is confirmed in the wild: it was added to the CISA KEV catalog on 2021-11-03 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days. No public PoC is listed in the provided data, but credential theft tied to this bug has been widely reused by threat actors. Do: Apply the patched FortiOS release per Fortinet's vendor advisory immediately, as this is a CISA KEV required action; if the fixed version is not known from this data, follow Fortinet's FG-IR-18-384 advisory for the correct upgrade path. Rotate SSL VPN credentials and review VPN access logs for path-traversal requests, since successful exploitation exposes plaintext session credentials, and restrict SSL VPN portal exposure to trusted sources where possible. | 9.8 | 100% | KEV ransomware |
| mass≈500,000 internet-exposed FortiOS SSL VPN portals (Fortinet cited ~480,000 affected devices) |
Full article296 words · extracted from infosecurity-magazine.com · click to collapse
Bangkok Airways has admitted that a cyber-attack last week led to the compromise of an unspecified volume of passengers’ personally identifiable information (PII).
The Thai airline claimed in a brief update late last week that although the incident didn’t affect “operational or aeronautical security systems,” it does appear as if personal data has been accessed.
Personal data could include full name, nationality, gender, phone number, email and home address, contact details, passport and historical travel information, partial credit card info and special meal information.
“This incident has been reported to the Royal Thai police as well as providing notification to the relevant authorities. For primary prevention measures, the company highly recommends passengers to contact their bank or credit card provider and follow their advice and change any compromised passwords as soon as possible,” the notice continued.
“In addition to that, the company would like to caution passengers to be aware of any suspicious or unsolicited calls and/or emails, as the attacker may be claiming to be Bangkok Airways and attempt to gather personal data by deception (known as ‘phishing’).”
Although the airline itself didn’t specify how the attackers compromised its IT systems or their intent, the notice appeared online at around the same time as ransomware group LockBit 2.0 published info on the attack.
A tweet citing its leak site claimed the group had 103GB of stolen files from the firm it planned to release.
LockBit 2.0 was also blamed for a compromise at global consultancy Accenture earlier this month. The Australian Cyber Security Centre (ACSC) published details on the group, which first appeared in June, on its website.
It revealed that LockBit 2.0 had been exploiting the CVE-2018-13379 vulnerability in Fortinet FortiOS and FortiProxy in an attempt to gain initial access into victim networks.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/bangkok-airlines-attackers-stole/