The Desk · The Wire · Hacked Today? · Data Center RSS
The Perimeter Site

Why Did They Keep 220 Million Passports?

The Perimeter Desk
2026-09-09
# Why Did They Keep 220 Million Passports? The most staggering number on the wire this morning isn't a CVSS score or a ransom demand. It's nine years. Vietnam's Advance Passenger Information System (APIS) spent nearly ten years quietly hoarding traveler records; now about 220 million of them have leaked. It isn't just names and flight numbers (though those are there), but full passport details. Companies love blaming some "sophisticated attacker" when this happens. There's nothing sophisticated about leaving the door unlocked for nine years; the real problem was the retention policy, or the fact that they didn't have one at all. Government procurement types treat data as an asset to hoard instead of a liability to manage. Bureaucrats keep everything just in case it helps them later. That choice pushes all the risk onto 220 million people whose identities are now floating around in the ether. The second-order effects are worse. This isn't just a list of tourists. It includes diplomats, corporate executives, and intelligence officers who crossed the border over the last decade. A dataset this granular is a goldmine for state-sponsored targeting, and it tells you exactly who visited Vietnam, and more importantly, who has been there consistently since 2017. When does a national security database stop protecting the border and just become a massive, unencrypted honeypot for every adversary in the region? While governments are busy hoarding data they can't protect, the people we pay to manage our infrastructure are handing out the keys. N-able patched a pre-authentication remote code execution flaw in N-central, known as CVE-2026-86218, and the bad news is that people are already exploiting it. If you aren't familiar with how Managed Service Providers operate, this is basically "god mode. N-central lets an MSP manage hundreds of client environments from one spot, and that means a single successful hit on one instance doesn't just burn one company. It hits every single customer that provider manages. It feels like the SolarWinds mess from 2020. Both cases highlight the systemic trust we put into centralized management. The difference here is simpler, and attackers don't always need a complex supply chain injection when they can find a pre-auth RCE and just walk through the front door. Why do MSPs use these tools? Efficiency. It lets them handle 50 clients with a skeleton crew. But that efficiency builds a concentration of risk that no insurance policy actually covers. When a management tool fails, the fallout ripples downstream immediately, and the small businesses and mid-market firms involved didn't choose to trust N-able. They trusted their provider, who trusted software with a critical hole in it. Then we have Microsoft, which spent its most recent patch cycle trying to plug nearly 1,000 security holes. The number is almost funny. When a vendor drops patches for 974 vulnerabilities at once, they'll tell you it shows diligence; they call it a commitment to security. It isn't. It's an admission that their codebase is a sprawling mess of legacy contradictions. Two flaws, CVE-2026-85880 and CVE-2026-81963, are already being exploited in the wild according to CISA. This is where the human element breaks. It's called patch fatigue. A sysadmin doesn't see 1,000 fixes on a Tuesday as a win. They see it as a paralysis; how do you validate every change without crashing your production environment? The company will probably call this record-breaking update a victory for transparency. That changes to an excuse the moment they tell users to just keep their systems updated. It's bad advice. It ignores the person clicking install on 974 different fixes, knowing one of them could kill the primary database. People in this industry love talking about reducing the attack surface. We're doing the opposite. We consolidate trust into a few vendors like Microsoft for the OS and N-able for management and government systems for identity. Then we act surprised when one flaw triggers a systemic collapse. Technology is the most targeted sector this week with 329 stories. That stat is misleading. Tech isn't just a target; it's the conduit. Who is the victim when an MSP tool or a passport database fails? It isn't the software company or the government agency. It's the traveler whose passport is on a forum and the small business owner who didn't know their provider used a vulnerable version of N-central. We are pricing in the cost of the software, but we aren't pricing in the cost of the catastrophe. Keep an eye on MSP insurance renewals if you want to see what happens next, and premiums will move once underwriters figure out that these efficiency tools are just fast ways to deliver RCEs. Right now, the incentives favor convenience over actually surviving. The Vietnam leak shows that data doesn't just vanish, and it sits there and gains value until someone finds the door. Now 220 million people know their government's idea of secure storage was basically a digital filing cabinet left on the sidewalk for nine years.
◼

Sources

The reporting this analysis was built from. Follow the originals before acting on anything here.

  1. N-able N-central Pre-Auth RCE Flaw Exploited in the Wild The Hacker News
  2. N-able Patches Critical Zero-Day in N-central SecurityWeek
  3. Microsoft Plugs Nearly 1,000 Security Holes Krebs on Security
  4. Google warns of new Chrome zero-day bug exploited in attacks BleepingComputer
  5. Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited The Record
  6. Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day SecurityWeek
  7. Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell The Hacker News
  8. MikroTik Patches Critical Flaws Chained to Hack Routers SecurityWeek

How stories are selected and rated

← More from the Desk Live Wire →

About · Methodology · Contact · Privacy

Tracking a CVE from this story? Hazard shows which vulnerabilities are confirmed exploited in the wild — and what the resulting breaches have cost UK organisations.

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.