Academic researchers are set to present a physical-access attack against Boeing 737 systems at the Usenix Cybersecurity Conference, according to Wired. The work comes from researchers at the University of California at San Diego and Oberlin College, who tested whether an aircraft could be compromised not through remote internet exposure, but through brief, covert access to onboard systems. Wired reports that the team built a roughly coin-sized, Wi-Fi-enabled prototype device costing less than $100. In the researchers’ account, the implant can be fitted in under 60 seconds through a port reachable via a hatch on the plane’s exterior. The outlet says that access point can be within reach of maintenance workers or other airport and airline staff between flights. The researchers say the device can send electrical signals over one of the 737’s internal networks and spoof commands to sensitive systems. Wired reports that the technique could redirect the aircraft’s autopilot navigation or silently alter values used in takeoff and fuel calculations, while also spoofing the information shown to the pilot. The values cited in Wired’s report are not incidental. The researchers described manipulating variables such as total aircraft weight and outside air temperature, which are inputs used in 737 takeoff calculations. They argue that subtle changes could create serious consequences, including runway overruns, unintended diversions, or crashes, though the provided report frames these as potential outcomes of the technique rather than documented real-world incidents. The project was not a quick proof of concept. Wired says the research stretched over more than a decade and required purchasing tens of thousands of dollars’ worth of aircraft components for testing. That detail matters: the claim is not that any casual attacker can improvise the attack, but that well-resourced saboteurs with brief physical access may represent a practical threat model. The researchers are withholding the specific port they targeted and some details of how the implant spoofs commands to aircraft computers, according to Wired. The report also says the researchers have worked closely with Boeing, but the provided material does not include Boeing’s full response or any regulator statement. For cybersecurity teams, the report is a reminder that “air-gapped” or offline systems are still exposed to physical-access attacks. In aviation, the risk model is especially sensitive because large numbers of trusted personnel, contractors, and ground operations workers interact with aircraft between flights. The researchers’ point, as described by Wired, is that security assumptions around brief access windows may deserve renewed scrutiny. Who benefits: Aircraft-security researchers and defenders get a concrete threat model to test against. Airlines, manufacturers, and regulators may also benefit if the work leads to tighter controls around exterior access points and maintenance procedures. Who's exposed: The exposure, as Wired frames it, is greatest for aircraft environments where brief exterior access is possible and internal systems trust signals on sensitive networks. The report does not establish that the technique has been used in the wild.