Visualização de leitura

Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data

An exposed Vietnam-linked APIS database contained 220.8 million passenger and crew records, including passport and flight data.

Researchers found an exposed Advance Passenger Information System (APIS) database containing 220.8 million passenger and crew records from January 2017 to April 2026.

The data includes sensitive details such as passport numbers, identities and flight information, potentially affecting travelers of many nationalities who flew to, from or through Vietnam. Kinryū Labs discovered the Elasticsearch cluster, named “pax-info,” while searching for exposed databases.

It contained 29 indices and about 107 GB of data. The researchers linked the server to IP space assigned to Viettel in Hanoi, but could not confirm which Vietnamese organization operated it.

Researchers found an exposed APIS database linked to Vietnam that contained more than 220 million passenger and crew records from 2017 to 2026. The data included passport numbers, identities and flight details. The Elasticsearch database, discovered by Kinryū Labs, held about 107 GB of data across 29 indices. It was hosted on IP addresses assigned to Viettel in Hanoi, although researchers could not confirm which Vietnamese organization operated the system.

The exposed database contained names, dates of birth, sex, nationalities, passport or travel-document numbers, expiration dates and issuing countries, BleepingComputers reports.

It also included flight numbers and dates, airlines, departure and destination airports, transit airports, seat numbers, baggage references, and scheduled, estimated and actual flight times. The database covered many airlines across Asia-Pacific, Europe and the Middle East, so it could affect people from around the world who traveled to or through Vietnam between 2017 and 2026.

Kinryū Labs confirmed the data was real by matching records with its researchers’ own trips to Vietnam. The total also counts travel records, not unique people, so frequent travelers may appear multiple times.

While the researchers could not provide a complete breakdown by nationality, the data covered numerous international airlines across Asia-Pacific, Europe, and the Middle East. As a result, the exposed records could relate to people from virtually anywhere who visited or transited through Vietnam over the nine-year period.

Kinryū Labs verified that the information was legitimate by matching records in the database against its researchers’ own travel to Vietnam.

The figures represent travel records rather than unique individuals. Passengers and crew members who flew multiple times may therefore appear repeatedly in the database.

Kinryū Labs reached the exposed database by combining two security misconfigurations. Direct internet access returned a 401 error, but another cloud-based path exposed the cluster and accepted default credentials.

FOFA first detected the host in 2022 and identified it as a database in 2023, but researchers could not determine when the passenger data became accessible. The records cover more than nine years, but the actual exposure period remains unknown.

Kinryū Labs reported the issue to Vietnamese authorities, affected airlines and national CERTs on June 3. The database was secured by June 8, with Singapore Airlines helping coordinate the response.

Researchers found no evidence that the listed airlines operated the system or suffered a network breach. They also found no ransom notes or signs that attackers had altered the database.

However, without server logs, they could not determine whether anyone had copied or stolen the data before the system was secured.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, APIS)

Linux Kernel 7.1 Reaches End of Life

The Linux Kernel 7.1 EOL has officially arrived. Discover the final updates and learn why you must upgrade to the latest stable LTS releases immediately.

Related Posts:

The post Linux Kernel 7.1 Reaches End of Life appeared first on Daily CyberSecurity.

Slovakia Warns of Cyber Risks in Road Speed Cameras

Slovakia warns that vulnerable speed cameras could expose vehicle data, enable remote access and provide attackers with a foothold into public networks.

Slovakia’s National Security Authority, NBÚ, recently issued a warning about several road speed cameras, calling them a significant cyber threat. The alert is not about someone deleting a speeding ticket. It is about connected devices that collect vehicle data, communicate with other systems, and may contain remote-access functions that the operator cannot fully control.

The Slovak authority examined a sample of the NERO R-ONE camera system at the request of the Interior Ministry. It named three product lines in its warning: NERO R-ONE devices sold by Cyprus-based SODASUS, Cordon-series speed cameras made by Russia’s Simicon, and Cordon-series products sold by Croatia’s NEROline.

“The National Security Authority warns of a significant cyber threat associated with the use of several types of road speed cameras.” reads the alert. “A security analysis has identified several risks and recommends that affected entities identify the products in question in their infrastructure.”

The problems went beyond a simple configuration issue. NBÚ found differences between the documented and actual communication settings, uncertainty about where the hardware and software came from, software that did not match the declared version, and weak security protections.

“The security analysis identified several risks, including the true origin of the camera hardware and software, inconsistency between the documented and detected configuration of the product’s communication interfaces, and pre-configured remote access and product management mechanisms.” the agency wrote on LinkedIn.

That last point deserves attention. A road camera should be managed by the organisation that owns it, under controls that it can inspect, configure and audit. If a device includes pre-set remote-access or management mechanisms outside the customer’s full control, it creates a blind spot in a system that may sit on a public-sector network or communicate with other operational services.

Speed cameras do much more than take pictures and measure speed. They photograph vehicles, record timestamps, process licence-plate data, store evidence and send information to backend systems used by authorities. Depending on the setup, they may also connect to mobile networks, roadside equipment, police systems, municipal platforms or third-party maintenance services.

If attackers compromise a camera, they could access data, change or delete records, manipulate how it measures or reports violations, or shut it down. If the network lacks proper segmentation, they could also use the camera as a foothold to reach other systems. The camera may not be the real target. It could simply be the unlocked door.

The warning aims to alert essential-service operators and other organisations that these road cameras could pose a serious cybersecurity risk. In the wrong circumstances, attackers could use them to disrupt networks, systems or services.

The Slovak Interior Ministry reportedly took the equipment out of its pilot deployment while the matter was investigated. Public reporting also says the ministry asked the supplier to remove the units and replace them with equipment meeting Slovak and EU legal, technical and security requirements.

The Russian connection adds an obvious geopolitical dimension, but it should not become a substitute for technical analysis. NBÚ did not say that every device was actively spying on users or that the equipment contained a proven backdoor. Its warning is about identified security risks, limited operator control, uncertainty over hardware and software provenance, and remote-management mechanisms that could not be fully accounted for.

That is enough reason to take action. Security checks for connected public devices cannot rely only on the brand, the country listed on the invoice or the vendor’s claims. Operators should know exactly what software and firmware the device runs, how remote access works and who controls it. They should also use independent security testing, secure updates and network segmentation.

The same lesson applies beyond Slovakia. Smart cameras, licence-plate readers, parking sensors, environmental monitors, traffic lights and roadside communication systems are becoming part of public infrastructure. They are often cheap, easy to overlook and managed by public agencies, contractors and manufacturers. That makes them just as important to secure as other critical systems.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Speed Cameras)

2.2 Million Vehicles Exposed to KARR Bluetooth Security Flaw

KARR Security System

Millions of drivers with a dealer-installed KARR Security System are being urged to update their KARR alarm using an iPhone or Android device after researchers uncovered a Bluetooth vulnerability that could allow nearby attackers to unlock or immobilize affected vehicles.   The flaw impacts more than 2.2 million vehicles equipped with the aftermarket security system, but it does not affect factory-installed vehicle software, Apple CarPlay or Apple's iPhone platform. 

KARR Security System Vulnerability Affects Dealer-installed Hardware 

The KARR Security System is installed by dealerships to secure vehicles on their lots. In many cases, the hardware remains connected even after buyers decline the paid KARR alarm service. Because it is third-party equipment, automakers cannot deliver fixes through their standard software update process.  Researchers from the University of California, San Diego found that attackers within Bluetooth range could lock or unlock vehicles, disable alarms, activate horns, flash lights, or prevent parked vehicles from starting. However, they confirmed the flaw cannot remotely start a vehicle or control it while driving. 

iPhone App Update Fixes KARR Alarm Flaw 

Acrisure Protection Group, which sells the KARR Security System, released a firmware update on July 20 after researchers privately disclosed the issue in January 2025. Owners using the KARR Security app on an iPhone should receive an update notification. Others must download the app, connect it to the KARR alarm, then navigate to "Customer Service" and "Firmware Update." The patch was released before presentations scheduled for DEF CON on August 9 in Las Vegas and the USENIX Security Symposium on August 12 in Baltimore.

Hidden KARR Security System Complicates Updates 

Researchers estimate at least half of affected owners never requested the KARR Security System. Dealerships often left deactivated hardware installed, yet researchers found these units continued broadcasting Bluetooth signals while vehicles were running and for up to 10 minutes after being switched off. Owners can identify the system by checking for a KARR or "SWDS" sticker on the driver's window or a blinking button beneath the dashboard. Most affected vehicles were purchased from Honda, Toyota, Mazda, Ford and Jeep dealerships in Southern California between 2017 and July 21, although impacted vehicles were also identified elsewhere.

Shared Bluetooth Key Exposes KARR Alarm Devices

Researchers discovered a universal authentication key embedded in the official smartphone app while reverse engineering Bluetooth communications. Using a proof-of-concept Android app, they unlocked vehicles, disabled KARR alarm functions, and triggered horns and lights. Although the flaw alone cannot steal a vehicle, researchers said it could provide quiet access before a commercially available locksmith tool creates a working key. Acrisure described the attack as "highly complex" and said the real-world risk is low. Neither UC San Diego nor Wired found evidence of criminals exploiting the vulnerability.

Privacy Concerns and Recommended Action

Researchers also warned that Bluetooth signals from the KARR Security System could reveal vehicle locations. Using the WiGLE wireless database, they estimated at least 2.2 million Bluetooth-enabled systems had been deployed and detected 97 KARR-equipped vehicles during a 20-minute drive near the UC San Diego campus.  Drivers should confirm whether their vehicle contains a KARR Security System, install the latest firmware using the iPhone or Android app, and contact their dealership or KARR support if they cannot complete the update. 

AI Cyber Attacks Emerge as Biggest Threat to Indian Banking: RBI

AI Cyber Attacks

The Reserve Bank of India (RBI) has identified AI Cyber Attacks as the biggest near-term cybersecurity threat facing the Indian banking system, according to the June 2026 edition of its Financial Stability Report (FSR). The central bank's latest assessment highlights that while banks and financial institutions have strengthened cyber risk management practices, rapid advances in artificial intelligence are making cyber threats more difficult to counter. The findings are based on a survey conducted by the RBI to assess the preparedness of major banks and non-banking financial companies (NBFCs) against evolving cyber risks. The survey found that institutions have established robust cybersecurity practices, particularly in vulnerability assessment and penetration testing of critical systems. However, AI Cyber Attacks emerged as the most significant challenge expected over the next 12 months.

AI Cyber Attacks Lead RBI's Cyber Risk Assessment

According to the RBI Financial Stability Report, AI-enabled cyber threats can increase the speed, scale and sophistication of attacks targeting financial infrastructure. Survey responses showed that most financial institutions are still in the developing or intermediate stages of integrating AI-specific threat preparedness into their existing cybersecurity frameworks, while only a smaller number reported mature capabilities. The report states that continued improvements in threat monitoring, detection, response mechanisms, employee awareness and cyber resilience will remain critical as AI-powered attacks continue to evolve.

Cybersecurity Practices Improve, But Gaps Remain

The RBI noted that financial institutions have made significant progress in cyber risk management. Regulatory reporting processes and board-level reporting of major cyber incidents have also matured. However, the report identified employee cybersecurity awareness and training as areas requiring further improvement, noting that human behaviour remains one of the most exploited entry points for cyberattacks. It also highlighted the need to strengthen forensic preparedness to improve incident response, preserve digital evidence and support regulatory and law enforcement investigations following sophisticated cyber incidents. The survey further revealed that around 67 percent of respondents increased IT and cybersecurity staffing between March 2025 and March 2026. Additionally, 71 percent reported higher cybersecurity spending as a share of overall IT expenditure during the last three financial years.

Third-Party Risk Emerges as Second Biggest Concern

Beyond AI Cyber Attacks, the RBI ranked third-party risk and supply chain dependencies as the second most important cybersecurity challenge for the financial sector. The survey found that 93 percent of respondents rely partially or substantially on external vendors for cybersecurity functions such as security operations centre monitoring, cloud security, incident response, threat intelligence and vulnerability assessments. Three-fourths of respondents also reported moderate to very high dependence on third-party technology providers for critical applications. According to the RBI, a major cyber incident affecting a common service provider could rapidly disrupt multiple regulated entities and create broader financial stability risks.

Growing Digital Transactions Increase Cyber Risk

The report noted that cyber risk has become a major financial stability concern as India's financial ecosystem becomes increasingly digital and interconnected. About 79 percent of surveyed institutions said more than three-fourths of their customer transactions are now conducted through digital financial services. Although 98 percent of respondents rated their current cyber risk exposure as very low to moderate and reported minimal disruption to customer services during 2025-26, nearly one-third indicated that cyber risk had increased compared with the previous year. The RBI also observed that geopolitical uncertainty is contributing to the evolving threat landscape, with 42 percent of surveyed institutions believing it has increased the likelihood of cyberattacks.

Financial Sector Cybersecurity Strategy Advances

The report said the proposed Financial Sector Cybersecurity Strategy is at an advanced stage of formulation. Developed by an Inter-Ministerial Group under the Financial Stability and Development Council, the strategy aims to establish governance frameworks, regulatory harmonisation and implementation timelines across the financial sector. The RBI said the strategy will address cybersecurity risks associated with artificial intelligence, cloud computing, quantum technologies, third-party dependencies, consumer protection and cross-sector critical infrastructure, strengthening the resilience of India's financial system against emerging cyber threats.

One Railway Radio Outage Stopped Trains Across Germany and Nobody Knew Why

A nationwide GSM-R outage stopped trains across Germany, exposing how one aging communications system can still bring an entire rail network to a halt

At 10:30 PM on Tuesday June 23, Deutsche Bahn told passengers something that had never happened before for technical reasons: all trains across Germany were being held at their stations.

The company confirmed the outage was caused by a nationwide failure of its GSM-R system, the Global System for Mobile Communication for Railways, which handles internal communication across the entire rail network. Without that link, running trains safely isn’t possible, so nothing moved.

“All trains are suspended in Germany’s most populous state, North Rhine-Westphalia.” reported the German media outlet DW.

That line alone gives you the scale. Berlin’s public transport authorities confirmed that municipal, regional, and long-distance Deutsche Bahn trains were all affected. The Berlin S-Bahn suspended all trains on all lines. Stuttgart halted everything on its network.

Deutsche Bahn CEO Evelyn Palla spoke to Bild newspaper in the early hours and was candid about where things stood:

“We are now trying to get the trains into stations so that travelers can disembark. And then we have to fix the problem, which we don’t yet know.” Deutsche Bahn CEO Evelyn Palla said.

That quote is doing a lot of work. The head of one of Europe’s largest rail operators, publicly admitting she didn’t yet know what had broken her entire network.

Engineers identified the cause of the disruption within roughly ninety minutes of the first announcement, and the network came back online just before 1 a.m. Deutsche Bahn said technicians were working around the clock and later confirmed the fix was successful. The company apologized to passengers and said it would issue taxi and hotel vouchers to those affected, with replacement buses arranged where possible.

The Stuttgart S-Bahn’s statement to passengers during the outage captures exactly the kind of uncertainty that cascaded across every station in the country.

“At present, all S-Bahn trains across the entire network are being held at platforms.” said authorities in Stuttgart. “Please check your journey in the travel information system for alternative transport options. We will inform you as soon as we have new information and can assess how long the disruption will last.”

Which is the polite way of saying: we have no idea how long this will last.

GSM-R is a railway-specific version of 2G mobile technology, deployed across Europe since 2000 as the standard for voice and data communications between drivers and control centers. Deutsche Bahn has already signed with Nokia to replace it with a 5G system using the Future Railway Mobile Communication System standard. That replacement hasn’t arrived yet, which means the network that failed Tuesday night is still the one everything depends on. No evidence of a cyberattack or physical infrastructure damage has emerged. The exact technical cause of the failure has not been publicly disclosed. Deutsche Bahn is already notorious for frequent delays and cancellations. A complete nationwide technical halt, in calm weather, with no external cause, is a different category of problem from a late train.

At this time, the situation appears normal; however, as of 6:30 AM, DB warned “some isolated disruptions may still occur” and advised passengers they’ll need to check that their connections will run on time.

The Register confirmed that there is no evidence that the outage was caused by a cyberattack or by physical infrastructure damage such as cut cables. The incident nevertheless raises questions about resilience, as critical infrastructure networks are expected to include multiple layers of redundancy to prevent widespread disruptions. The organization praised its IT team, stating that its experts worked tirelessly and successfully restored services.

In August 2023, Poland’s Internal Security Agency (ABW) and national police launched an investigation into a hacking attack on the state’s railway network. According to the Polish Press Agency, the attack disrupted the traffic overnight.

Stanisław Zaryn, deputy coordinator of special services, told the news agency that Polish authorities were investigating the unauthorized usage of the system used to control rail traffic.

Since the beginning of the Russian invasion of Ukraine, Poland’s railway system has represented a crucial transit infrastructure for Western countries’ support of Ukraine.

Zaryn explained that the attacks are part of a broader activity conducted by Russia to destabilize Poland.

In April 2024, the Czech transport minister Martin Kupka warned that Russia conducted ‘thousands’ of attempts to sabotage European railways.

The Czech Republic’s transport minister told the Financial Times that the attacks aim to destabilize the EU and sabotage critical infrastructure.

Kupka confirmed that Russia-linked threat actors have conducted “thousands of attempts to weaken our systems” since the beginning of the Russian invasion of Ukraine.

The state-sponsored hackers also targeted signaling systems and networks of the Czech national railway operator České dráhy, Kupka said.

The Czech cyber defense was able to detect and neutralize these attacks; however, the minister highlighted that sabotaging railways could cause serious accidents.

At the end of October 2022, a cyberattack caused trains in Denmark to stop; it hit a third-party IT service provider. The attack hit the Danish company Supeo, which provides enterprise asset management solutions to railway companies, transportation infrastructure operators, and public passenger authorities.

DSB is the largest train operating company in Denmark.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

Critical Ghost CMS Vulnerability Exploited to Hack 700+ Websites

CVE-2026-26980

A critical Ghost CMS vulnerability identified as CVE-2026-26980 has been exploited in a widespread cyber campaign that compromised more than 700 websites, including platforms associated with major institutions such as Harvard University, University of Oxford, and DuckDuckGo. Security researchers say the attacks leveraged weaknesses in the Ghost content management system to inject malicious JavaScript code aimed at facilitating ClickFix malware attacks.  The attacks were detailed by Chinese cybersecurity company QiAnXin and its XLab research team, which warned that threat actors are actively exploiting unpatched Ghost installations in an ongoing “large-scale poisoning” campaign. 

CVE-2026-26980 Enabled Unauthorized Access to Ghost CMS Sites 

The exploited flaw, tracked as CVE-2026-26980, was disclosed and patched in February 2026 in version 6.19.1 of the Ghost content management system. Ghost is a widely used open-source CMS focused on blogging, digital publishing, newsletters, and memberships. According to its developers, the platform powers more than 100,000 websites globally.  The Ghost CMS vulnerability is an SQL injection flaw affecting Ghost’s Content API. Researchers at SentinelOne previously warned that the vulnerability could allow unauthenticated attackers to extract sensitive data directly from a site’s database. This included authentication tokens, website content, and user credentials.  The flaw received a CVSS severity score of 9.4, highlighting the serious risks posed by CVE-2026-26980. The vulnerability was reportedly discovered by Anthropic using its Claude AI system. What made the Ghost CMS vulnerability especially dangerous was its ability to expose a site’s Admin API Key. Once attackers obtained this key, they could abuse Ghost’s Admin API to directly modify published articles and inject malicious code into legitimate websites without authorization.

Hundreds of Websites Infected 

According to QiAnXin XLab, attackers began exploiting CVE-2026-26980 shortly after the security patch became publicly available. Investigators noted that a DLL file involved in the campaign carried a compilation timestamp dated February 16, 2026 — the same day the patch for the Ghost CMS vulnerability was announced. The malicious activity was first detected on May 7, 2026, and by early May, researchers had already identified hundreds of compromised websites running the Ghost content management system. More than 700 websites across various industries were eventually found to be affected. The victims included organizations operating in sectors such as artificial intelligence, software development, blockchain, cybersecurity, fintech, media, SaaS, and higher education. Researchers found that nearly half of the compromised websites were personal blogs or independently operated sites. However, many others belonged to major institutions and technology-focused organizations.  QiAnXin stated that many victims were notified about the compromises, but the majority reportedly failed to respond to the alerts.  “At least two groups are currently actively conducting such poisoning operations, and some sites have even become the target of competition between the two parties, with different malicious code being implanted one after another within a single day,” the researchers said. 

Malicious JavaScript Injected Into Ghost CMS Articles 

The attackers used the Ghost CMS vulnerability to tamper with website articles by appending malicious JavaScript loaders to the bottom of pages. These loaders were designed to support ClickFix attacks — a growing social engineering tactic that tricks users into manually executing malware on their systems.  The injected code acted as a two-stage loader that retrieved additional payloads at runtime from an external domain identified as “clo4shara[.]xyz/11z77u3.php.” Researchers said the infrastructure gave attackers flexibility to swap payloads while maintaining the same loader framework across multiple compromised Ghost CMS sites.  QiAnXin explained that the PHP script functioned as a traffic distribution and cloaking system powered by Adspect, a commercial cloaking service. The script gathered browser fingerprinting data from visitors and selectively redirected targets based on predefined rules.  “Directly accessing clo4shara[.]xyz/11z77u3.php reveals a piece of code, which is actually a typical traffic distribution script,” XLab researchers explained. “Its core function is to collect various fingerprint information from the user's browser and upload it to the server, then perform actions such as redirection, popups, and downloads based on the returned instructions.”  The cloaking mechanism helped attackers avoid detection by ensuring that only intended victims received malicious payloads, while automated scanners and crawlers were shown harmless web content instead. 

Kuwait Banks Deploy Real-Time War Room to Fight Growing Cyber Fraud Threats

Kuwait cyber fraud threats

Kuwait’s banking sector is strengthening its defenses against rising Kuwait cyber fraud threats with the deployment of an advanced virtual operations system designed to detect and respond to financial crimes in real time. The initiative, led by the Kuwait Banking Association, comes under the direction of the Central Bank of Kuwait as part of a broader effort to counter increasing fraud targeting bank customers.

Virtual War Room Enhances Financial Cybercrime Response

Officials say the newly enhanced platform, often described as a virtual war room banking system, has evolved into a centralized national mechanism to tackle Kuwait cyber fraud threats more effectively. According to Abdulwahab Al-Duaij, head of the Anti-Fraud Committee at the association, the system enables banks and authorities to act quickly when fraud is detected. It connects directly with government bodies, including the Ministry of Interior and the Public Prosecution, allowing coordinated action without delays. This level of integration is seen as a critical step in addressing financial cybercrime Kuwait, where speed often determines whether stolen funds can be recovered.

Real-Time Action to Stop Fraudulent Transactions

One of the key features of the system is its ability to respond immediately to incidents. Once suspicious activity is identified, the platform allows authorities to halt transactions, trace the movement of funds, and begin legal proceedings. This rapid response capability is central to tackling Kuwait cyber fraud threats, which increasingly involve fast-moving digital transactions that can be difficult to track after the fact. Officials say the banking fraud detection system has already improved the efficiency of handling fraud cases, reducing response times and limiting financial losses for customers.

Shift From Reactive to Proactive Monitoring

The upgraded system marks a shift in how Kuwait cyber fraud threats are managed. Instead of reacting only after fraud occurs, the platform now actively monitors patterns and emerging tactics used by attackers. Authorities have identified a range of common scams, including fake bank communications, fraudulent links requesting data updates, misleading advertisements, and false prize claims. These tactics are designed to trick users into sharing sensitive information. By tracking these patterns, the system aims to detect suspicious activity earlier and prevent fraud attempts before they succeed.

Coordination Strengthens National Cyber Defense

The collaboration between banks, law enforcement, and regulatory bodies is a key part of the strategy. Officials say this coordinated approach improves visibility into threats and ensures that responses are aligned across institutions. As Kuwait cyber fraud threats continue to evolve, such coordination is becoming increasingly important. Financial fraud is no longer limited to isolated incidents but often involves organized networks using multiple channels to target victims. The virtual chamber serves as a central hub where information can be shared quickly, enabling faster and more informed decision-making.

Customers Urged to Stay Vigilant

While the system strengthens institutional defenses, officials stress that customer awareness remains essential in reducing Kuwait cyber fraud threats. Users are being warned not to share banking details, passwords, or one-time codes under any circumstances. Banks have reiterated that they do not request such information through phone calls, text messages, or online links. Many recent fraud cases have relied on social engineering techniques, where attackers impersonate trusted entities to gain access to sensitive data.

Ongoing Efforts to Address Emerging Threats

The Kuwait Banking Association says the virtual system will continue to evolve as new fraud techniques emerge. The goal is to maintain a high level of readiness and ensure that financial institutions can respond effectively to changing risks. As digital banking adoption grows, Kuwait cyber fraud threats are expected to remain a key concern for both regulators and financial institutions. Strengthening detection systems and improving response coordination are likely to remain central to the country’s cybersecurity strategy. Officials say the focus will remain on protecting customer assets, maintaining trust in the banking system, and ensuring that fraud cases are addressed quickly within legal frameworks.

Information Stored in European Passports

Discover how European biometric passports work. Explore RFID chips, Data Groups (DG1-DG3), MRZ encryption, and the tech behind the Schengen Entry/Exit System.

The post Information Stored in European Passports appeared first on Security Boulevard.

❌