Aviation authorities report ‘less than 5%’ flight cuts despite Mideast war Fewer than 5 per cent of Hong Kong flights for May and June combined have been cancelled, and about 1 per cent for the peak July travel period, aviation authorities have said, despite a global fuel crisis triggered by war in the Middle East. The figures were shared in Secretary for Transport and Logistics Mable Chan’s response to a lawmaker’s question, with the minister also revealing the Airport Authority planned to review charges to ease the financial burden on the aviation industry. The Civil...
Original (en)
Fewer than 5 per cent of Hong Kong flights for May and June combined have been cancelled, and about 1 per cent for the peak July travel period, aviation authorities have said, despite a global fuel crisis triggered by war in the Middle East. The figures were shared in Secretary for Transport and Logistics Mable Chan’s response to a lawmaker’s question, with the minister also revealing the Airport Authority planned to review charges to ease the financial burden on the aviation industry. The Civil...
Published
May 6, 2026, 02:37 PM UTC
7d ago
Significance
Entities Detected
· click + to trackGoogle Threat Intelligence reports a sophisticated supply chain attack on axios NPM package versions 1.14.1 and 0.30.4 (March 31, 2026), where attackers injected malicious 'plain-crypto-js' dependency to deploy WAVESHAPER.V2 backdoor across Windows, macOS, and Linux platforms. Attribution to UNC1069 based on malware signatures, infrastructure overlaps, and operational patterns. Remediation guidance includes version pinning, dependency auditing, CI/CD pipeline security, and credential rotation.
A critical remote code execution vulnerability (CVE-2026-1731) has been identified in remote monitoring and management software that could be exploited to deploy ransomware and compromise supply chain integrity. The flaw enables attackers to execute arbitrary code, creating significant risk for downstream organizations and critical infrastructure.
A supply chain attack campaign utilizing sleeper packages has been identified, distributing malicious payloads that enable credential theft, GitHub Actions tampering, and SSH persistence mechanisms. The attack is attributed to the GitHub account 'BufferZoneCorp' which has published malicious Ruby gems and Go modules.
a51b8c56…openwatch.io →