The airline deactivated the network after the crew realized someone was messing with the in-flight system. The feds are investigating. The post Delta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las Vegas appeared first on CyberScoop.

Delta Airlines is investigating an incident on a flight from Las Vegas to Atlanta where a passenger reportedly deployed a rogue Wi-Fi network, leading to the deactivation of the aircraft's Wi-Fi system and a subsequent federal investigation. The incident occurred on Delta flight 591, which departed Harry Reid International Airport on Monday, August 10, 2026, after the conclusion of the DEF CON cybersecurity conference in Las Vegas.
According to Delta spokesperson Morgan Durrant, the cabin crew deactivated the aircraft's Wi-Fi functionality for approximately 30 minutes after realizing a passenger had set up an unauthorized network. Durrant confirmed that the flight's safety was never compromised and no aircraft operating systems were affected. Delta is conducting a full investigation and is collaborating with federal law enforcement and aviation regulators.
Messages from the aircraft's Communications Addressing and Reporting System (ACARS) indicated that the crew informed ground personnel about a passenger creating a network named "Delta WiFi Fast" and attempting to defraud other passengers. Social media posts detailing the incident went viral, claiming the rogue network could be used to steal sensitive data.
The Atlanta office of the FBI and the Federal Aviation Administration (FAA) have acknowledged awareness of the incident but have not provided further comment. The Transportation Security Administration (TSA) and Homeland Security Investigations (HSI) have not yet responded to inquiries.
The incident exhibits characteristics of an "evil twin" attack, a method where an attacker creates a fraudulent Wi-Fi access point that mimics a legitimate network's name and settings. Such attacks can trick devices into connecting to the rogue hotspot, allowing the attacker to monitor unencrypted internet traffic, perform man-in-the-middle attacks, or present spoofed login portals to harvest credentials and personal information.
The timing of the incident, occurring on a flight departing Las Vegas immediately after the annual DEF CON cybersecurity conference concluded on Sunday, August 9, 2026, has drawn particular attention. The flight itself was delayed, originally scheduled for Sunday but not departing until 8:30 a.m. Monday.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.