Cyber•3 reports
43DOOM SCORE
Airport group reportedly left API keys exposed in client-side JavaScript for four years
First seen: Sep 9, 2026, 3:17 PM UTCUpdated: Sep 9, 2026, 7:02 PM UTC
WHAT HAPPENED
A security researcher claims an airport group exposed API keys in client-side JavaScript for four years. The supplied report does not specify the airports, scope of access or whether the keys were exploited.
SO WHAT?
Exposed credentials could enable unauthorized access to airport-related systems or data, though the operational impact is not established.
FOR ME
Impact on Switzerland
Checking cached analysis...
MARKETS
Market impact
Checking cached analysis...
COVERAGE
Reports behind this event
aol.co.uken
'Baggage reclaim was pandemonium': passengers hit by airport IT chaos recount their ordeals
Sep 9, 2026, 7:02 PM UTC
theguardian.comen
'Baggage reclaim was pandemonium': passengers hit by airport IT chaos recount their ordeals | Airline industry
Sep 9, 2026, 6:46 PM UTC
theregister.comen
Security boffin claims airport group left API keys in client-side JavaScript for four years
Sep 9, 2026, 3:17 PM UTC