LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
security

Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal

A Department of Transportation rule published last week says that airlines complying with cybersecurity regulations will have reduced customer obligations in the event of an attack. The post Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal appeared first on CyberScoop.

zeroday.news ·

A new Department of Transportation (DOT) rule, effective next month, will reduce airline obligations to customers for flight delays or cancellations caused by cyberattacks, provided the carrier complies with applicable cybersecurity regulations. This change is part of a broader DOT rule published last week, which establishes a new category for tracking delay information and reduces air carrier responsibilities across ten specific types of events deemed "not controllable."

These ten events, including cyberattacks, mean airlines are no longer obligated under their customer service plans to provide amenities or compensation, such as meal vouchers or hotel stays, when disruptions arise from these causes. The DOT spokesperson indicated that Congress explicitly directed these changes in the FAA Reauthorization Act of 2024, aiming to ensure government delay data accurately reflects what airlines can and cannot control.

The rule's language regarding "applicable cybersecurity regulations" is intentionally broad, according to legal experts, likely to accommodate the unpredictable nature of cyberattacks and the varying regulations that might apply depending on the specific operational capabilities or information affected. Carriers unable to demonstrate compliance with these regulations will still be subject to customer and other requirements.

One airline consumer advocacy group, FlyersRights, expressed skepticism about the change, noting it was implemented without public comment. The group plans to monitor the impact on customers and any reduction in amenities, arguing that cybersecurity is an airline responsibility and delays should clearly not be due to carrier neglect, especially given the constant threat of cyberattacks. They have previously advocated for stress tests on airline computer systems.

Another group, the National Consumers League, offered a mixed view. While acknowledging the rule provides consumers with certainty regarding their rights across different airlines, they also expressed concern that the DOT appears inclined to make rules less onerous for the airline industry. Specifically, they worried about potential airline abuse of ambiguity related to "unscheduled maintenance," another of the ten events, to avoid compensating consumers.

The Aviation Information Sharing Analysis Center (Aviation ISAC) welcomed the elements of the rule related to incident reporting, stating that it supports efforts to simplify and harmonize cybersecurity reporting across government agencies. Legal analysis suggests the rule could be positive for both airlines, by providing clarity on disruptions outside their control, and for consumers, by offering a more accurate picture of carrier-controlled delays and cancellations.

While there is no formal accounting of how often cyberattacks have directly led to flight delays or cancellations requiring compensation, hackers have previously targeted airlines and the broader aviation sector. Examples include attacks by Scattered Spider last summer and an attack on Collins Aerospace last year that caused delays in Europe. The 2024 IT outage related to cybersecurity company CrowdStrike, which grounded flights, was not a cyberattack but did lead to some airline compensation, as the DOT determined that incident was within airline control.

The Biden administration previously imposed cybersecurity regulations on airports, aircraft owners, and aircraft operators in 2023 due to persistent cybersecurity threats in the sector. The newly published DOT rule stems from a Federal Aviation Administration authorization law signed by President Joe Biden in 2024.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.