Researchers from the University of California San Diego and Oberlin College disclosed a coin-sized hardware implant that can be attached to an accessible Boeing 737 avionics service port to spoof commands sent between the Flight Management Computer and the cockpit display interface. In Boeing test-lab demonstrations using a custom 737 avionics test bed known as Triton, the team showed the device could remain concealed under a dust cap, intercept avionics traffic, and alter data such as outside air temperature, aircraft weight, and flight-plan information, creating the potential for incorrect takeoff calculations or route deviations.
The researchers said they first shared the findings with Boeing more than six years ago and warned that aircraft redesign cycles could slow remediation if technical changes are required. Boeing said it reviewed component designs, installations, and interfaces and maintains that existing aircraft design and operational safeguards significantly limit real-world feasibility and risk, while the researchers recommended mitigations including blocking access to the service port, improving electrical isolation, and adding cryptographic protections to prevent spoofed avionics messages; the device was also reported to support remote access through in-flight Wi‑Fi.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
After spending years acquiring secondhand Boeing 737 computer components, the research team had assembled a wired-together avionics test bed called Triton. The platform enabled their later experiments on Boeing 737 systems.
In response to the researchers' findings, Boeing conducted its own review of component designs, installations, and interfaces. Boeing said existing design and operational protections significantly limit the feasibility and risk of real-world attacks.
The team demonstrated its attack in a Boeing facility test lab, showing interception, alteration, and spoofing of communications between the Flight Management Computer and the Multipurpose Control Display Unit. The attack used a coin-sized hardware implant attached to an avionics service port.
The researchers shared their physical-access Boeing 737 hacking findings with Boeing more than six years before the 2026 reporting. Their work showed that commands could be spoofed to aircraft computers through an undisclosed or service port.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
tomshardware.com
Open sourcewired.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.