220M Travel Records Exposed, Plus 4 Tech Stories
220 million travel records were exposed — but not 220 million people
A database that appears to be connected to a Vietnamese Advance Passenger Information System was left reachable online with more than 220.7 million passenger and crew records inside it. That is the first number you’re going to see in headlines today, and it is enormous. It also needs one immediate qualification: these are travel records, not 220 million unique people.
Advance Passenger Information Systems, or APIS, collect the identity and travel information airlines send to border authorities before passengers and crew arrive or depart. Researchers at Kinryū Labs found the exposed Elasticsearch cluster on June 3 while surveying internet-facing databases. According to BleepingComputer, it contained 210,318,069 passenger records and 10,465,631 crew records dating from January 2017 through April 2026. A person who flew through Vietnam ten times could therefore appear ten times.
The data itself is still plenty serious. Records included names, dates of birth, sex, nationality, passport or other travel-document numbers, document expiration and issuing country, flight numbers and dates, airlines, airports, seat assignments, baggage references and timestamps. The researchers checked samples against their own travel and BleepingComputer reviewed records covering multiple nationalities.
The technical failure was not one dramatically broken lock. The researchers described a chain of misconfigurations that ultimately made the Elasticsearch data accessible. The cluster was reported June 3 and the exposure was remediated by June 8.
Now the other important distinction: exposed does not automatically mean stolen. Neither Kinryū Labs nor BleepingComputer found evidence that criminals downloaded, sold or ransomed the database, and the organization operating it has not been publicly confirmed. There is also no victim list telling an ordinary traveler to replace a passport Tuesday morning.
So I wouldn’t manufacture an action item just to have one. I would take unusually convincing airline, immigration, passport and travel-themed phishing very seriously, especially when a message already knows where or when you traveled. That kind of context can make a fake message feel disturbingly legitimate. But right now the evidence supports a major data exposure, not a claim that 220 million people had their identities stolen.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
MikroTik routers with internet-facing SSH need an update now
CERT Polska says attackers are actively exploiting a two-vulnerability chain it calls MikroTrick against MikroTik RouterOS devices whose SSH service is reachable from the public internet. This one does have a very straightforward action item: update.
The first flaw, CVE-2026-67276, is an SSH authentication bypass. RouterOS did not compare an entire RSA public key correctly. If an attacker knew a username and part of the public-key information, they could construct a different key that RouterOS accepted without possessing the legitimate private key. The second flaw, CVE-2026-86060, lets a specially crafted username manipulate the resulting SSH session into full administrator privileges.
Put the two together and an attacker can go from no authentication to control of the router. CERT Polska says it has confirmed real attacks since at least September 2 and that the patched releases stop the observed exploitation.
Fixed versions are RouterOS 7.24.2, 7.23.4, 6.49.21 and 7.25beta3. MikroTik says most configurations are not at risk and its normal home-router configuration does not expose SSH to the internet, which is useful context. It is not an excuse for an administrator who deliberately exposed management services to leave the thing unpatched.
After updating, check for unknown users, scripts, scheduled tasks, proxies and tunnels. CERT Polska specifically warns that RouterOS’s new “Flagged” marker can identify some suspicious changes, but a clean marker does not prove the router was never compromised.
One interesting footnote: CERT Polska says the research used OpenAI’s GPT-5.5-cyber and GPT-5.6-sol models in an isolated lab. It also says every hypothesis was still tested on real RouterOS systems with negative controls and repeat testing. That’s a considerably more useful description of AI-assisted security research than “AI found six bugs.”
The boring machines need attention too
Browsers, workstations, remote-access tools, Wi-Fi, and ordinary office hardware rarely get much attention until one of them becomes the problem. Raymond Tec provides onsite IT and field services around Reading, Pennsylvania, along with practical help keeping the technology people use every day working and reasonably secure.
BigBear can steal a Microsoft 365 session after MFA succeeds
BigBear 2.0 is a phishing-as-a-service operation built around Evilginx2, and CloudSEK’s look inside its control panel is a useful reminder that “we have MFA” and “this account cannot be phished” are not the same statement.
This is an adversary-in-the-middle attack. The victim lands on a phishing site that proxies the real Microsoft sign-in page. The username and password pass through the attacker’s server on their way to Microsoft. The victim then completes MFA with Microsoft normally. Microsoft issues an authenticated session cookie, and that cookie also passes through the attacker’s proxy before reaching the victim.
The attacker does not have to break the second factor. The user successfully completed it. The attacker steals the browser session that Microsoft created after it.
CloudSEK says the panel contained 5,137 credential records, including 1,032 plaintext passwords, 4,148 session cookies and 474 completed MFA-bypassed authentications. BleepingComputer reports that 258 organizations suffered at least one completed compromise, while CloudSEK says 461 organizations were targeted across more than 40 countries.
BigBear also injects JavaScript intended to make FIDO2/WebAuthn appear unavailable so users fall back to weaker authentication methods. That matters because phishing-resistant passkeys and hardware security keys are bound to the legitimate website; a reverse proxy on the wrong domain cannot simply reuse that authentication the way it can replay a normal session cookie.
For businesses, the practical answer is not “MFA is useless.” It is almost the opposite. Move toward phishing-resistant authentication and make it difficult or impossible to fall back to SMS, TOTP or push approval for sensitive accounts. Conditional Access that requires a managed, compliant device adds another boundary. And if a login flow that normally offers your passkey suddenly insists you use a code instead, that is a very good reason to stop rather than helpfully work around the problem.
Mathspace says a missed patch exposed more than a million accounts
Mathspace updated its breach notice today and put a very specific number on the incident: 1,079,819 students, parents or guardians, teachers and staff in Australia and New Zealand were affected.
Attackers exploited a vulnerability in Mathspace’s self-hosted Metabase reporting system. Metabase published a critical advisory and patched versions on August 6, but Mathspace says its vulnerability-notification process failed to escalate that advisory. Unauthorized access began as early as August 10, data was downloaded August 27, and Mathspace updated the system August 29. The company also acknowledges that after updating it did not immediately perform the additional compromise checks recommended for a potentially affected system.
The exposed records included names, usernames, email addresses and account metadata such as last-login and last-active dates. Mathspace says passwords, password hashes, SSO tokens, API credentials, academic records, learning activity and assessment results were not exposed.
That makes the likely near-term risk targeted impersonation rather than somebody signing directly into Mathspace with a stolen password. A message that knows a student’s name and account details can look much more convincing than generic spam. Mathspace is telling affected users to verify unexpected messages independently and not disclose passwords or verification codes.
For organizations, the harder lesson is less glamorous: receiving a security advisory is not the same thing as having a process that gets the right advisory to the right person quickly enough to matter. And once a vulnerable system may have been exposed, patching it closes the door; it does not tell you whether somebody already walked through it.
Business IT goes well beyond the website
Your business also depends on workstations, cloud accounts, browsers, Wi-Fi, remote access, collaboration tools, and all the other technology that quietly becomes infrastructure. Raymond Tec works across that whole stack, whether the problem lives on a server, on a desk, or somewhere in between.
Australia wants people to choose whether the algorithm runs their feed
Australia released draft Digital Duty of Care legislation today with a proposal called “My Feed, My Way.” For social media users over 16, platforms would have to offer a choice: keep a default feed personalized by recommendation algorithms, or switch to a feed based on the friends and creators the user actually chose to follow.
I find that more interesting than another argument about whether recommendation algorithms are inherently good or evil. The proposal does not ban personalization. It makes the platform ask.
The broader draft goes further. Games, apps, AI chatbots, messaging services and other digital platforms would have duties to protect people under 18 from harmful content and design features with negative behavioral effects. Australia’s eSafety Commissioner would enforce the rules, and noncompliance could bring penalties of up to A$109.2 million.
There are obvious questions about how “harmful” design and content get defined and where safety rules start colliding with speech. Reuters notes free-speech advocates are already warning about censorship. Those arguments matter, but they are arguments about a draft. The government is consulting platforms, industry, civil-society groups and advocates now and says legislation will be introduced to Parliament later this year.
Nothing changes in somebody’s social-media app today. Still, the feed-choice idea is worth watching because it goes after a basic power imbalance in modern social media: the service normally decides what it thinks will keep you looking, and the user gets to fight the settings afterward. Australia is proposing that the user be offered that choice up front.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- BleepingComputer: 220 million traveler records exposed in Vietnam-linked APIS leak
- CERT Polska: Critical RouterOS vulnerabilities are being actively exploited
- MikroTik: September 2026 security advisory
- CloudSEK: Tracking the BigBear 2.0 Evilginx2 phishing campaign
- BleepingComputer: BigBear bypassed MFA at 258 organizations
- Mathspace: Data breach notice and investigation findings
- ABC News: More than 1 million users affected in Mathspace breach
- Prime Minister of Australia: My Feed, My Way
- Reuters: Australia targets social media algorithms with user-choice rules
