Slovakia finds Russian backdoor in traffic speed cameras
- ID
- 17126
- Status
- summarized
- Published
- 23 Aug 2026, 10:38 PM
- Fetched
- 24 Aug 2026, 3:28 AM
- Provider
- Hacker News
- Category
- dev-community
- Original URL
- https://risky.biz/risky-bulletin-slovakia-finds-russian-backdoor-in-traffic-speed-cameras/
- Source URL
- https://hnrss.org/best
Summary
- Score
- 5.5
- Created
- 24 Aug 2026, 3:29 AM
- Tags
- Audience
- developerssaas_founders
What happened
Slovakia's national security service NBU issued an alert against NERO R-ONE traffic cameras—rebranded Russian CORDON PRO.M units from St. Petersburg firm Semicon—after finding an SMS-triggered backdoor granting shell access from hardcoded Russian phone numbers. The cameras also ship with SecureBoot disabled, unauthenticated live video streams, and vulnerable web management portals. 279 units were purchased under a €30M EU-funded project before deployment was paused pending independent audit.
Why it matters
For any builder involved in government or enterprise IoT procurement in Malaysia and Southeast Asia, this is a concrete checklist of what to demand from hardware vendors: enforce SecureBoot, require authenticated streams, audit firmware provenance, and scrutinize rebranded products with opaque supply chains. The Cyprus shell company with fake certifications is a reminder that vendor due diligence must trace to the actual manufacturer, not the reseller.
Discussion angle
How would a Malaysian government agency or GLC even detect this kind of supply chain compromise—what procurement-stage technical checks would have caught the disabled SecureBoot or SMS backdoor before deployment?