A Government Accountability Office audit found significant weaknesses in how the Federal Aviation Administration and Transportation Security Administration manage aviation cybersecurity, raising concerns about the resilience of U.S. aviation systems. The FAA had fully implemented only three of seven cybersecurity strategy objectives, with gaps in cyber monitoring, incident response, privileged access controls, standards compliance, zero-trust migration planning, and complete reporting of cybersecurity spending. GAO warned that weaknesses such as poor patching and unsupported operating systems could disrupt communications and alter flight data, even though no successful cyberattacks on aircraft avionics have been reported.
The audit also found that the TSA is still relying on an outdated 2018 Cybersecurity Roadmap that does not clearly assign responsibility for securing airlines and airports or align with current Department of Homeland Security strategy, contributing to confusion and weak accountability across the sector. GAO issued five recommendations calling on TSA to update and clarify its roadmap and on FAA to improve budget reporting, zero-trust planning, and monitoring of its revised strategy; the review noted that FAA and TSA have cooperated effectively through the Aviation Cyber Initiative and that FAA certification and National Airspace System authorization processes generally addressed identified avionics cybersecurity practices.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
The audit recommended that TSA update and clarify its cybersecurity strategy and responsibilities, and that FAA improve implementation tracking, monitoring, zero-trust planning, and cybersecurity budget reporting. GAO issued five recommendations in total across the two agencies.
A Government Accountability Office audit found significant weaknesses in how the FAA and TSA govern and implement aviation cybersecurity. The audit said FAA had fully implemented only three of seven cybersecurity objectives, while TSA was still relying on an outdated 2018 roadmap that did not clearly assign oversight responsibility.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.