Skip to content
HN On Hacker News ↗

Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras

▲ 391 points 155 comments by dredmorbius 2w ago HN discussion ↗

Pangram verdict · v3.3

We believe that this entire text is human-written.

0 %

AI likelihood · overall

Human
100% human-written 0% AI-generated
SEGMENTS · HUMAN 1 of 1
SEGMENTS · AI 0 of 1
WORD COUNT 1,254
PEAK AI % 0% · §1
Analyzed
Aug 23
backend: pangram/v3.3
Segments scanned
1 windows
avg 1254 words each
Distribution
100 / 0%
human / AI fraction
Verdict
Human
Pangram v3.3

Article text · 1,254 words · 1 segments analyzed

Human AI-generated
§1 Human · 0%

Risky Bulletin Newsletter August 19, 2026 Written by Catalin CimpanuNews Editor This newsletter is brought to you by Socket Security. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here. 🗨The intro was updated post-publication to fix the link to the technical report and to add more context from a local source.Slovakia's national security service NBU has issued a security alert against the use of NERO R-ONE high-speed traffic cameras.The agency says the cameras contain a backdoor mechanism that grants shell and network access to the devices via an SMS message received from a list of hardcoded Russian phone numbers.The NBU started an investigation into the devices after the country's opposition accused the government of buying the cameras from Russia and after multiple reports in Slovak media that linked the purchase to a Cyprus shell company with fake certifications.According to the NBU, the cameras are a rebranded version of a Russian traffic camera model named CORDON PRO.M, produced by St. Petersburg-based Russian firm Semicon.via NBUvia NBUThe cameras were bought as part of a €30 million EU-funded project to rebuild the country's national traffic monitoring system.The Interior Ministry has allegedly bought and preparing to install 279 cameras on selected roads across Slovakia.The Ministry initially denied that the cameras were of Russian origin and said there's no danger of data theft since the devices were going to be on a closed loop Ministry network.According to an NBU technical report, besides the backdoor system, the cameras also contain several security flaws. They have a crucial SecureBoot security feature that's turned off so the firmware origin is never enforced, the web management portal contains multiple vulnerabilities, and the cameras expose live streams to anyone without a password and who knows their broadcasting IP.Interior Ministry officials paused the camera deployment after the NBU report and said it would order an additional assessment from an independent auditor to confirm the findings.Some similar devices are also allegedly installed in Croatia and maybe some other countries in Eastern Europe.Source Nobody should be buying security cameras from Russia, or China for that matter https://t.co/ZiuuZ3ODjQ— ChrisO_wiki (@ChrisO_wiki) August 18, 2026 Risky Business PodcastsIn this episode of Risky Business Features, James Wilson chats with PortSwigger’s Director of Research James Kettle about using an LLM to develop genuinely new attack techniques. Breaches, hacks, and security incidentsScammers target UK prime minister: A scammer targeted UK Prime Minister Andy Burnham by posing as White House chief of staff Susie Wiles. Burnham detected the scam himself and the UK embassy notified the White House. Multiple US senators, governors, and executives were also targeted by scammers posing as Wiles last year. The White House blamed the incident on a hacker obtaining a copy of her cellphone contacts. [Politico Europe]Hackers target Ukraine's ARMA agency: A cyberattack has disrupted the activities of Ukraine's agency for managing seized Russian assets. The attack took place this week as the agency was preparing to assign a new manager for beverage company IDS Ukraine. Ukraine seized IDS from Alfa-Bank co-founder Mikhail Fridman shortly after Russia's invasion. The agency didn't attribute the attack. [RBC // ARMA]Hack hits Berlin government: A cyberattack has disrupted two major departments in the Berlin city government. The attack took down emails, remote gateways, and internet connections across the transport and urban development departments. IT staff have disconnected the two agencies from the city network to prevent the incident from spreading. [Tagesspiegel // RBB24 // Yahoo Finance!]Breach at genetics testing company: Genetics-testing company Baylor Genetics is notifying users of a security breach that exposed their personal information. The breach took place in June and both patient and employee data was compromised. The company didn't disclose the number of affected individuals. [Baylor Genetics // CybersecurityDive]UT San Antonio breach: The University of Texas at San Antonio has taken its IT systems offline after a security breach over the weekend. Classes for the new school year are expected to start on Wednesday as scheduled. The university has extended tuition payment deadlines and plans to reset all user account passwords once systems are online. [UT San Antonio // The Record]Ransomware disables hospital doors, HAVC: A ransomware attack has disabled access doors, heating, ventilation, and air conditioning at Winnipeg's largest hospital. The Winnipeg Health Sciences Centre increased onsite security while the access card system is still down. The hospital says patient care and clinical operations are not impacted. [CBC // The Winnipeg Free Press] [h/t Alex Rudolph]BlueSky and GitHub hit by Iranian DDoS attacks: An Iranian hacktivist group took down BlueSky and GitHub with DDoS attacks on Sunday and Monday, respectively. The attacks caused prolonged outages at both companies. A group known as the 313 Team took credit for the attacks. The hackers were also behind another wave of DDoS attack in April. [Telegram // Telegram] We apologize for yesterday’s service problems. Bluesky experienced a DDoS attack—a flood of junk traffic meant to knock servers offline—over a period of 24 hours. We have upgraded our defenses in response, and we continue to monitor the situation. Follow @status.bsky.app for any updates.— Bluesky (@bsky.app) August 18, 2026 at 12:27 AM SafePal breach: Hackers have stolen the personal information of 40,000 customers of hardware crypto-wallet provider SafePal. The incident impacted all customers who placed orders of SafePal wallets between March 2, 2025, and April 11, 2026. SafePal says no seed phrases or private keys are impacted. The stolen data is still dangerous because it could enable wrench attacks on wallet holders. [SafePal // SecurityWeek]Bits of Gold breach: Hackers have stolen the data of 250,000 customers of Bits of Gold, Israel's largest cryptocurrency exchange. The company notified customers of the hack over the weekend. It said the data was stolen from an external analytics service provider. It didn't say what type of data was stolen. [CTech]TheHatman dumps employee data for a dozen companies: A threat actor is selling the employee data of almost a dozen Fortune 500 companies. The hacker, who goes by TheHatman, claims the data was stolen by using stolen credentials to access each victim's Azure environments. The hacker claims they breached McDonalds, Vodafone, Gap, and the Intercontinental and Wyndham hotel chains. [HudsonRock]AI, general tech, and privacyWindows 11 drops WMIC: The current Windows 11 installation packages and Insider Builds do not ship with the Windows Management Instrumentation Command-line (WMIC) feature anymore. Microsoft deprecated the toolkit a few years ago after it saw massive abuse. [Microsoft // WindowsLatest]Firefox 154: Mozilla has released Firefox 154. New features and security fixes are included. The biggest feature in this release is support for GeForce NOW, NVIDIA's cloud gaming platform. [Firefox]Firefox for iOS gets an ad blocker: Mozilla has added an ad blocker to Firefox on iOS. It is turned off by default. [Mozilla]Government, politics, and policyRussian things: A Russian court has forced two Telegram channel owners to remove posts blaming the country's internet watchdog for causing an outage of the country's banking system as part of an attempt to block VPN protocols. This is funny to me because they didn't fine Natalya Kaspersky, one of the Kaspersky co-founders, for basically saying the same thing in an official manner and to more mainstream Russian news outlets. Alas, Russia, a two-tiered society! [Caution News on Telegram]In this Risky Business sponsor interview, Casey Ellis chats with Socket founder Feross Aboukhadijeh about npm 12’s move to disable install scripts by default.