How EFB Data Reaches the Cockpit: Charts, Updates & Connectivity
From AIRAC cycle to cockpit: the complete EFB data pipeline — chart production, ground distribution, connectivity options, sync and version control.
Hands-on cybersecurity tutorials, CVE breakdowns, and guided learning paths. Every technique is explained, tested, and paired with its mitigation — so you learn the attack and the defense together.
From AIRAC cycle to cockpit: the complete EFB data pipeline — chart production, ground distribution, connectivity options, sync and version control.
On 28 February 2020, Virgin Media confirmed that a marketing database containing the personal details of around 900,000 people had been left insecure and accessible online, discovered not by criminals but by a researcher during unrelated work. The dataset, stored on an unsecured cloud instance, included names, home and email addresses, and phone numbers, and had been reachable for at least ten months. This post explains exactly what was exposed, how the misconfiguration happened, how Virgin Media responded, and what happened next: a textbook non-hack data breach that still required full disclosure, notification, and regulatory scrutiny.
On 20 February 2020, CISA published AA20-030A, a joint advisory describing how ransomware had disrupted a natural gas compression facility: a phishing link let commodity ransomware spread from IT into the OT network, encrypting data historians and polling servers, severing HMI visibility, and leaving operators blind to real-time pressure and flow data for two days. The advisory became a reference model for oil and gas asset owners because it mapped, step by step, how a single email chained into loss of operational visibility without directly controlling pipeline equipment. This retrospective walks through the kill chain, the defensive gaps, and the guidance that followed.
On 11 March 2020, Microsoft shipped a fix for CVE-2020-0796, a wormable remote code execution flaw in how Windows 10 and Windows Server handle compressed SMBv3 packets. An attacker could send a specially crafted compressed packet and trigger a buffer overflow before authentication, exactly the class of bug security people fear could be chained into self-spreading malware. Researchers named it SMBGhost, published proof-of-concepts within days, demonstrated local privilege escalation chains, and Microsoft followed with an out-of-band patch update on 12 March. This technical retrospective covers the flaw mechanics, the compression workaround, the patch wave, and why the wormable nightmare never fully materialized.
On 24 March 2020, Reuters reported that hackers had stood up a near-identical malicious imitation of the World Health Organization’s internal email portal, infrastructure aimed at stealing passwords from staffers coordinating the global pandemic response. The same reporting documented that around 450 active WHO email addresses and passwords, plus thousands more belonging to people working on the COVID-19 response, had been leaked online. It was not an isolated incident but part of a documented surge in targeting of health bodies that spring. This piece reconstructs the verified incidents of March 2020 and the wider lesson that crisis response organizations are priority intelligence targets.
At the end of March 2020, Marriott disclosed its second major breach in two years: the login credentials of two franchise properties had been abused in late February 2020 to siphon 5.2 million guest records, including names, addresses, phone numbers, birthdays, loyalty details, and in some cases travel itineraries and room preferences. Unlike the 2018 Starwood catastrophe that exposed up to 383 million records, this intrusion was caught and contained within weeks, but it reignited regulatory scrutiny on both sides of the Atlantic. This retrospective covers the intrusion path, the data involved, the disclosure timing, and the aftermath for one of hospitality’s biggest names.
On 20 March 2020, the FBI’s Internet Crime Complaint Center published a public service announcement warning that cyber criminals were exploiting the COVID-19 pandemic at scale: phishing lures referencing stimulus payments and fake cures, malicious apps, and infrastructure spoofing health authorities. It was one node in a broader wave of official guidance that spring, with CISA and the UK’s NCSC issuing joint advice on pandemic-era remote work and video conferencing security, and IC3’s later reporting would show complaint volumes surging through 2020. This retrospective explains what the warning said, what the threat landscape actually looked like that spring, and how a global crisis became an attack-surface multiplier.
Type A, B and C EFB software explained — from document viewers to certified performance tools. How failure effects drive aviation software classes.
Post-quantum crypto migration is just the beginning. Crypto agility strategies to survive future cryptographic transitions.
A practical guide to agentic AI security covering goal hijacking, tool misuse, identity and privilege abuse, memory poisoning, multi-agent trust issues, and defense frameworks for autonomous AI systems.
A practical analysis of API security authorization flaws behind modern breaches. Covers BOLA, BFLA, IDOR, mass assignment, shadow APIs, and defense strategies for API-first architectures.
Trace the evolution of phishing attacks from crude 1990s email scams to AI-powered deepfake campaigns. Discover how attackers leverage machine learning and automation to create convincing social engineering attacks.