Researchers discovered a SQL injection vulnerability in the FlyCASS system, which is used by some airlines to manage access to the Known Crewmember (KCM) and Cockpit Access Security System (CASS) programs. This vulnerability allowed them to add unauthorized users to the system, potentially granting them access to airport security checkpoints and cockpit areas. The researchers reported the issue to the Department of Homeland Security, which initially responded promptly but later stopped communicating and issued incorrect statements about the vulnerability. The issue has since been remediated, but the incident raises concerns about the security of airport systems and the response of authorities to vulnerability reports.