Skip to content
June 21, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Technology
  • Next-generation aircraft ID systems are vulnerable to hacking
  • Technology

Next-generation aircraft ID systems are vulnerable to hacking

Do Son January 24, 2018 3 minutes read
Add as a preferred
source on Google

The U.S Government Accountability Office (GAO) submitted a report to the U.S Congress that pointed out that there are still unresolved cyber-security issues in the U.S. “broadcast automatic related surveillance” technology (ADS-B Out) the Hostile States and unauthorized individuals and organizations may use real-time data broadcast by military aircraft (in flight) to perform a variety of malicious activities.

GAO did not provide details. As part of the Federal Aviation Administration’s (FAA) Next-Generation Air Systems modernization program, the ADS-B Out system is designed to make it easier for third parties to access data to track and determine the condition of an aircraft without having to maintain a private database.

ADS-B Out: Automatic broadcast-related monitoring

Automatic acquisition of parameters from relevant airborne equipment without manual intervention or interrogation Placement of aircraft information such as position, altitude, speed, heading, identification number, etc., for the aircraft to monitor.

 

ADS-B system features

The FAA hopes to modernize ground-based radar systems using the Satellite-based system via ADS-B, enabling automatic reporting of aircraft positions, automatic navigation, and digital communications.

The ADS-B provides accurate position information for both high-altitude and airport-parked aircraft. It covers a wider area than traditional radars, helping to reduce the risk of collisions, providing pilots with real-time alerts and providing more accurate location information during inclement weather. The FAA requires that all aircraft in the U.S. airspace be equipped with ADS-B by January 2020 and that military aircraft be no exception. The DOD and other federal agencies have been very concerned about this technology for years.

GAO said that with the help of existing technology, the public can access the aircraft’s International Civil Aviation Organization (ICAO) addresses (including aircraft models, codes such as aircraft’s 24-digit electronic identification code), answering machines or “calling” codes and heights to track certain aircraft. ADS-B made these flight data available in a timely manner for military aircraft, but some of the data were confidential for some aircraft.

What security risks may be brought?

According to the report, foreign intelligence agencies, terrorists, and criminals may identify and track the aircraft through existing technologies. The FAA fears that switching to a radar system will cause problems when it switches to ADS-B. The U.S. military is concerned that the military aircraft’s broadcast information is vulnerable to cyber-attacks and that the operation of the military aircraft by the state, individuals, and organizations may occur.

Extensive assessments by the U.S. Department of Defense (DOD) and the Federal Aviation Administration confirmed that there is a security risk in ADS-B Out technology that could expose aircraft, tactical air traffic control systems, and FAA radars to countries, individuals or organizations Launched electronic warfare, cyber attacks and other types of interference activities.

So far, the FAA and the U.S. Department of Defense have been focusing on the installation of equipment and have not yet solved their security problems with military aircraft. The U.S. Defense Department advises shielding military identifiers, allowing military aircraft pilots to turn off ADS-B and other solutions. So far, the United States Department of Defense and the Federal Aviation Administration have not approved any mitigation.

Related coverage

  • The Hype Hangover: Dell Admits Consumers Aren’t Buying the “AI PC” Narrative
  • Orbital AI: Google Unveils Project Suncatcher to Launch TPU Data Centers into Space
  • Google Appeals to Supreme Court to Halt Injunction from Epic Games Lawsuit
  • Moonshot AI Unleashes Kimi K2: Trillion-Parameter Open-Source Model Outperforms Grok, Powers Perplexity
  • Galaxy Z Fold7 & Flip7 Leaked: Samsung’s Thinnest Foldables Yet Unveiling July 9 at Unpacked

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Next-generation aircraft ID

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-5366CVSS 9.9
    Prefect version 3.6.23 is vulnerable to remote code execution due to improper...
  • CVE-2024-58351CVSS 9.8
    Flowise before 2.1.4 allows configuration to be injected into the Chainflow during...
  • CVE-2022-50972CVSS 9.8
    WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to...
  • CVE-2019-25763CVSS 9.8
    WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability...
  • CVE-2026-11551CVSS 9.8
    The Branda plugin for WordPress is vulnerable to privilege escalation via account...
  • CVE-2026-56081CVSS 9.1
    Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker...
  • CVE-2026-56073CVSS 9.4
    Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that...
  • CVE-2026-55447CVSS 9.6
    ### Summary All components based on `BaseFileComponent` are vulnerable to the following...
  • CVE-2026-48584CVSS 9.9
    Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to...
  • CVE-2026-48582CVSS 9.6
    Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • GreatXML BitLocker Bypass: Public PoC Exploit Disclosed
  • Check Point VPN Vulnerability Exploited in the Wild with Ransomware Links
  • Weekly Threat Intelligence: June 1 to June 7, 2026
  • Cisco SD-WAN Vulnerability Exploited in the Wild with Root RCE Risks
  • Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.