Researchers Ian Carroll and Sam Curry discovered a vulnerability in FlyCASS, a third-party web-based service that some airlines use to manage the Known Crewmember (KCM) program and the Cockpit Access Security System (CASS). KCM is a Transportation Security Administration (TSA) initiative that allows pilots and flight attendants to skip security screening, and CASS enables authorized pilots to use jumpseats in cockpits when traveling. The process involves scanning a KCM barcode or entering an employee number, then cross-checking with the airline's database to grant access without requiring a security screening. Similarly, the CASS system verifies pilots for cockpit jumpseat access when they need to commute or travel.
Become a member and receive exclusive videos and other advantages:
/ @secprivaca
You can also buy me a coffee here:
https://buymeacoffee.com/secprivaca