The Government Accountability Office published a report Monday finding that the FAA has not completed risk assessments or updated security documentation for systems vulnerable to spoofing, jamming, and cyberattack. Two text-messaging systems used to communicate with aircraft predate modern cybersecurity standards and lack basic protections like encryption. The FAA cannot detect most interference in real time — it investigates after the fact, once pilots or controllers report something wrong. The same morning, the FAA ordered ground stops at Newark Liberty International, Philadelphia International, and Teterboro airports after radio frequencies at the Philadelphia Terminal Radar Approach Control (Tracon) failed. Arrivals and departures at Newark were delayed. The FAA has not said what caused the outage. There is no public evidence linking the disruption to the vulnerabilities described in the GAO report, but the timing illustrates the brittleness the report diagnoses. The GAO's findings are specific. Investigators warned that a hacker could send fraudulent messages — including false cancellations of flight clearances — to aircraft, with potential to cause delays, disrupt airspace, or create safety risks. Seven of eight reviewed systems lack formal risk assessments. The watchdog issued nine recommendations: complete those assessments, build continuous monitoring for interference and spoofing, and establish formal guidance on information sharing. The Department of Transportation, responding for the FAA, agreed with all nine. Senator Ron Wyden of Oregon, who sits on the Senate Intelligence Committee, called the findings a "major threat to US national security, to our economy and the safety of the flying public." Wyden has long campaigned on cybersecurity issues and framed the problem as a failure to require the aviation industry to use secure communications. His statement pointed to the risk from both hackers and foreign governments exploiting these vulnerabilities. The international dimension is real. Estonia and Finland have accused Russia of interfering with satellite navigation in their airspace — Moscow denies it. Last September, a Spanish military jet carrying the country's defense minister experienced GPS disruption over Russia's Kaliningrad exclave. The GAO report explicitly noted jamming and spoofing incidents abroad as part of the threat landscape the FAA must address. Monday's disruption is the latest in a pattern at Newark. In April 2025, an outage blanked controllers' screens for 60 to 90 seconds and cut contact with aircraft. The FAA subsequently moved the Philadelphia Tracon to a new fiber-optic link with New York on two separate paths. That fix addressed one failure mode but does not touch the deeper problem: the systems themselves were designed before adversarial cyber threats were a serious consideration. The FAA handles more than 44,000 flights and about 3 million passengers daily. Every one of those flights depends on communication systems the GAO has now documented as unencrypted, unmonitored in real time, and lacking basic risk assessments. The Department of Transportation agreed to all nine recommendations. The question is speed — and whether the FAA's modernization pace can outrun the threat landscape that state-sponsored actors and technically capable adversaries already inhabit.