WEEKLY HIGHLIGHTS
July 31 – August 9
TOP STORY
Pilots don’t carry paper anymore. Everything is on a tablet, and that tablet pulls what it needs over ordinary Wi-Fi. CYVIATION researchers placed a fifty-dollar phone next to a real airline-issued Electronic Flight Bag loaded with the briefing for an actual scheduled flight. It took seconds.
From that one seat, they compromised the EFB, took an entire network offline, filled the air with spoofed networks passengers could not distinguish from real ones, and intercepted Bluetooth devices. The phone went through airport security in a pocket without a second look. Security took the nail scissors and waved it straight through.
What makes it possible is that the radios inside a phone were never limited to the job they were sold for. At 35,000 feet there are a few hundred people sitting shoulder to shoulder for hours sharing the same airwaves, and not one of them can step out of range. None of this even has to work for a flight to suffer, which is the strangest part of all. Two aircraft were grounded this year over nothing more than a device name. Both were jokes. The full investigation is on the CYVIATION website.
ALSO THIS WEEK
One Facility, Two Hours, Nine States: What the Minneapolis ARTCC Outage Reveals About Aviation’s Resilience Assumptions
On August 6, an equipment failure at Minneapolis Center knocked out both radar and voice communications across a nine-state region for two hours. The outage was not a cyberattack, and that distinction matters. But a facility designed with purpose-built redundancy going to ATC Zero from an equipment failure alone exposes exactly the class of structural concentration point that cyber risk planning needs to account for. If the operational impact looks like this without an adversarial component, the risk picture with one is a question worth asking now.
A Preliminary NTSB Report Puts Military GPS Jamming at the Center of a Fatal Medevac Crash
The NTSB has released a preliminary report on the May 14 crash of a medevac flight in New Mexico, finding that military GPS jamming from a scheduled electronic warfare exercise was active in the area when the aircraft lost navigation shortly after takeoff. All four people aboard were killed when the aircraft struck a mountain ridge. The jamming was briefly paused on request, then resumed several minutes before the crash. This is believed to be the first documented case of military GPS jamming linked to a fatal civilian crash in U.S. airspace.
REGULATORY WATCH
The European Commission has published an update to its civil aviation occurrence reporting rules, formally adding uncrewed aircraft systems, U-space airspace events, and Part-IS information security incidents to the list of occurrences organizations are required to report.
The change brings drone and U-space operations into the same reporting rigor long applied to crewed aviation, and it links information security incidents under Part-IS directly to the EU’s core occurrence reporting infrastructure rather than leaving them in a separate process.
SKYRAY INSIGHT
This week’s four stories span the full range of aviation’s connected attack surface. A hands-on research demonstration shows what is reachable from a single passenger seat using hardware that costs fifty dollars and clears security every time. A fatal crash links military GPS jamming to a loss of navigation at a critical phase of flight. An equipment failure at a single FAA facility takes nine states of airspace offline for two hours without any adversarial involvement at all. And Europe formally extends its mandatory reporting infrastructure to cover information security incidents for the first time.
The thread connecting all four is dependency without visibility. A flight deck depending on an EFB whose wireless surface nobody is actively monitoring. A crew depending on a GPS signal they have no way to verify. A national airspace system depending on redundancy that failed alongside the system it was supposed to back up. A reporting architecture that, until this week, had no formal category for the information security events already happening inside it.
SkyRay supports aviation organizations in understanding exactly what they are running, what it connects to, and where the dependencies are, before those dependencies surface in an incident rather than an audit.
FROM THE CYVIATION TEAM
The lead story this week is our own. A fifty-dollar phone. A real airline-issued EFB. A single seat. The question we set out to answer was simple: how much of what we assume is secure in the cabin is secure because of a decision someone made, and how much is secure because the tools to challenge it used to be expensive and rare? The answer, at least for the wireless layer around an Electronic Flight Bag, is mostly the second one. That stopped being a safe assumption some time ago.
Alongside it, two stories that ask the same question from a different direction. A medevac crew that lost GPS navigation during an active jamming exercise. A redundant FAA facility that still went to ATC Zero. In each case the system did what it was designed to do, right up until it didn’t. The gap between design intent and operational reality is where most of this week’s stories live, and it is the gap that aviation cybersecurity exists to close.
Discover how SkyRay delivers aircraft-level cyber intelligence, continuous threat visibility, and actionable insights to help aviation organizations strengthen cybersecurity and operational resilience.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.