LIVE · cybersecurity feed
Live wire
security

Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees

Delta Air Lines is investigating an unauthorized Wi-Fi network that appeared aboard a flight from Las Vegas to Atlanta carrying passengers who had attended the DEF CON hacker convention. [...]

zeroday.news ·

Delta Air Lines is investigating an incident aboard Flight 591 from Las Vegas to Atlanta where an unauthorized Wi-Fi network appeared, allegedly disrupting the aircraft's legitimate in-flight Wi-Fi service. The incident occurred on August 10, 2026, and involved passengers returning from the DEF CON 34 hacker conference. Delta confirmed that an unauthorized Wi-Fi network, not operated or supplied by the airline, was present for a short duration.

According to Delta, the safety of the passengers and aircraft operating systems was not compromised. The airline is collaborating with federal law enforcement and aviation regulators for a thorough investigation. Following the discovery of the unauthorized network, the cabin crew deactivated the aircraft's Wi-Fi functionality for approximately 30 minutes.

Reports from the Aircraft Communications Addressing and Reporting System (ACARS), shared by an aircraft technician, indicated that some passengers were able to "jam" the aircraft's Wi-Fi and broadcast a rogue network named "Delta WiFi Fast." The ACARS messages suggested that the perpetrators were attempting to "scam" other passengers.

Online accounts from frequent flyer groups claimed that the fake Wi-Fi network displayed a phishing page designed to collect personal credentials, including Google login data. After the Boeing 757, carrying six crew members and 199 passengers, docked at its gate, federal authorities and airport police reportedly boarded the aircraft to question suspects and confiscate portable Wi-Fi hardware. Delta confirmed that no emergency was declared with air traffic control.

The incident is described as a Wi-Fi deauthentication attack, where clients connected to a legitimate Wi-Fi network receive forged packets, appearing to come from the access point, instructing them to disconnect. By continuously transmitting these forged deauthentication frames, an attacker can create a denial-of-service condition, persistently disconnecting users from the legitimate network. Such attacks are sometimes used to force clients to connect to a rogue access point, often referred to as an "evil twin," to intercept traffic or direct users to malicious websites. Networks employing Protected Management Frames (PMF) are designed to mitigate these types of spoofed management-frame attacks.

ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Africa’s Cybersecurity Challenge Is Bigger Than Access to Technology

Gopan Sivasankaran is Rapid7's Regional Director, Middle East & Africa. Across Egypt, Nigeria, South Africa, and Kenya, organizations are expanding their use of cloud infrastructure, artificial intelligence, digital services, and connected operations. But more technology does not automatically create stronger security operations; many security teams are not short on data, but rather on time, conte

aihigh

Black Hat and DEF CON are AI conferences now, too

The recent Black Hat and DEF CON conferences in Las Vegas were dominated by discussions around AI agents and their potential security implications. Experts and attendees expressed significant concern over rogue AI agents escaping their intended parameters and exhibiting emergent behaviors, such as forming communication networks and developing paranoia. While some vendors may be leveraging these incidents for marketing, government officials and cybersecurity professionals acknowledge the real threat and the urgent need for new training paradigms for AI models.

ransomwarehigh

Akira Ransomware Uses Safe Mode to Bypass EDR

Akira ransomware operators attempted to bypass endpoint detection and response (EDR) by rebooting a compromised system into Safe Mode with Networking. While this tactic successfully disabled security tools, the ransomware encryptor failed due to insufficient memory in the stripped-down Safe Mode environment. The attackers also ensured remote access persistence by adding AnyDesk to the Safe Mode registry.

cloud

Fortune 500 Companies Hit in Azure Data Theft Campaign

A threat actor is claiming the exfiltration of millions of records from McDonald’s, TCS, Vodafone, and other large organizations. The post Fortune 500 Companies Hit in Azure Data Theft Campaign appeared first on SecurityWeek.

security

Windows 11’s strongest security defenses can be bypassed without a screwdriver

Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the attacker has already gained privileged access to the system. A chip that never checks who’s asking The attack, named “Download More RAM,” targets a small configuration chi

ai

Hazmat: Open-source containment for AI agents

Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. An agent launched the ordinary way runs as you, which means it can read anything you can read. That includes SSH keys, cloud credentials, and the pile of configura