NASA Terminal Facility Guidelines for Unauthorized Disclosure of Personal Information (PII)

Disclosed by
FengSY
Summary by National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program

File has been removed from the media library.

Summary by FengSY

This situation increases risk of:

  1. Spear-phishing using exact internal contact details.
  2. Social engineering that bypasses authentication by referencing real names/phone numbers.
  3. Potential pretexting attacks on security, transport or logistics staff.

Recommendation:

  • Review directory access controls for /uploads and ensure sensitive docs are not publicly downloadable unless explicitly approved.
  • Remove or redact unauthorized content from this specific file.
Activity