Tech News Roundup — September 14, 2026 (NOON)

A quiet midday cycle brought two notable security stories: a university research team’s proof-of-concept hardware attack against Boeing 737 avionics, and a stealthy zero-click WhatsApp fraud campaign spreading across southern Europe.
Boeing 737 can be hacked in under a minute with a coin-sized device

A team from the University of California San Diego and Oberlin College built a coin-sized, sub-$100 device that can compromise a Boeing 737’s flight computer in under a minute. The attack targets an exposed service port on the aircraft’s underside that connects into the internal circuit bridging flight computers and pilot consoles, letting an attacker inject commands. The root cause is the aircraft’s use of ARINC 429, a 1970s-era avionics data protocol with no encryption or sender authentication — any device physically connected to the line is treated as a legitimate source. The researchers validated the technique in a dedicated lab built from real decommissioned aircraft parts, over a multi-year project; the device itself hides under the service port’s cover, packs a Wi-Fi-enabled microcontroller, and can be attached in under 15 seconds without special tools. Potential consequences include gradual navigation-route tampering and corrupted weight/balance/temperature parameters that could mislead takeoff power calculations. Boeing says real-world risk remains low thanks to airport security, tarmac surveillance and aircraft redundancies, and has been notified to evaluate mitigations, with the interim advice to isolate unnecessary connectors.
Zero-click WhatsApp attack drains iPhone contacts without a single tap

Security authorities have flagged a new zero-click WhatsApp attack targeting iPhones that requires no link click or QR scan from the victim. The campaign chains a flaw in iOS builds prior to 16.7.12 with a vulnerability in WhatsApp’s iPhone app, letting attackers remotely execute commands and take over the app. Once inside, criminals read the victim’s conversations to identify high-value contacts, then send urgent money-transfer requests that appear to come from the victim’s own legitimate number — and immediately delete the fraudulent messages using WhatsApp’s “delete for me” feature so only the victim’s own device retains a trace, leaving the account owner unaware anything happened. First documented in Italy, the wave has spread quickly across the Iberian Peninsula with victim counts already above the norm for this class of threat. Apple and Meta have shipped fixes closing the exploited entry points; users are urged to update iOS to the latest build and force-update the WhatsApp app via the App Store immediately.
Compiled from the configured RSS feed.