<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[220 million traveler records exposed in Vietnam-linked APIS leak]]></title><description><![CDATA[<p dir="auto">An exposed Advance Passenger Information System (APIS) database linked to Vietnamese aviation infrastructure left roughly <strong>220 million</strong> passenger and crew records publicly accessible. The cache included names, passport numbers, dates of birth, nationalities, and flight details, with entries spanning <strong>2017 to 2026</strong>.</p>
<p dir="auto">Researchers found the cloud-hosted system reachable via a public path that still accepted <strong>default credentials</strong>, allowing unrestricted read access without any authentication bypass or sophisticated exploit. The dataset reportedly covered both passengers and crew members, raising concerns regarding long-term identity theft and targeted phishing campaigns.</p>
<ul>
<li>Exposed data: full names, passport numbers, dates of birth, nationalities, and flight itineraries.</li>
<li>Timeframe: records from 2017 through 2026.</li>
<li>Root cause: default credentials left active on a cloud-based APIS instance.</li>
<li>Access method: direct connection to the exposed system using vendor-default login details.</li>
</ul>
<p dir="auto">The findings underscore persistent risks tied to misconfigured cloud deployments and unchanged factory settings, especially in border-control and travel infrastructure. It remains unclear whether the operator has restricted access or rotated credentials since the disclosure. Travelers whose data may be involved should monitor for unsolicited communications referencing flight history or passport details.</p>
<p dir="auto">Source: <a href="https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak" target="_blank" rel="noopener noreferrer nofollow ugc">BleepingComputer</a></p>
<p dir="auto">For those in travel or aviation security, how is your organization auditing cloud-facing systems for default credential usage, and would a discovery like this prompt an immediate review of your APIS or PNR handling procedures?</p>
]]></description><link>https://xploitlk.com/topic/259/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 06:14:19 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/259.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 08 Sep 2026 08:30:49 GMT</pubDate><ttl>60</ttl></channel></rss>