【文章标题】:Slovakia finds Russian backdoor in traffic speed cameras
【文章标题中文翻译】:斯洛伐克在交通测速摄像头中发现俄罗斯后门

【文章正文】:
Risky Bulletin Newsletter
《风险公报》通讯

August 19, 2026
2026年8月19日

Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras
《风险公报》:斯洛伐克在交通测速摄像头中发现俄罗斯后门

Written by
作者

News Editor
新闻编辑

This newsletter is brought to you by Socket Security. You can subscribe to an audio version of this newsletter as a podcast by searching for “Risky Business” in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.
本期通讯由 Socket Security 赞助。您可以通过在播客客户端中搜索“Risky Business”或通过此 RSS 订阅源订阅本通讯的音频版本。您还可以通过此处将 Risky Business 通讯添加为 Google 搜索结果的首选来源。

Slovakia’s national security service NBU has issued a security alert against the use of NERO R-ONE high-speed traffic cameras.
斯洛伐克国家安全局 NBU 已发布安全警报,警告不要使用 NERO R-ONE 高速交通摄像头。

The agency says the cameras contain a backdoor mechanism that grants shell and network access to the devices via an SMS message received from a list of hardcoded Russian phone numbers.
该机构表示,这些摄像头包含一个后门机制,可通过从硬编码的俄罗斯电话号码列表收到的短信授予对设备的 shell 和网络访问权限。

The NBU started an investigation into the devices after the country’s opposition accused the government of buying the cameras from Russia and after multiple reports in Slovak media that linked the purchase to a Cyprus shell company with fake certifications.
在该国反对派指责政府从俄罗斯购买这些摄像头,以及斯洛伐克媒体多次报道将这笔采购与一家持有虚假认证的塞浦路斯空壳公司联系起来之后,NBU 开始对这些设备展开调查。

According to the NBU, the cameras are a rebranded version of a Russian traffic camera model named CORDON PRO.M, produced by St. Petersburg-based Russian firm Semicon.
据 NBU 称,这些摄像头是俄罗斯交通摄像头型号 CORDON PRO.M 的换牌版本,由总部位于圣彼得堡的俄罗斯公司 Semicon 生产。

The cameras were bought as part of a â¬30 million EU-funded project to rebuild the country’s national traffic monitoring system.
这些摄像头是欧盟资助的 3000 万欧元项目的一部分,该项目旨在重建该国的国家交通监控系统。

The Interior Ministry has allegedly bought and preparing to install 279 cameras on selected roads across Slovakia.
据称,内政部已购买并准备在斯洛伐克各地选定的道路上安装 279 个摄像头。

The Ministry initially denied that the cameras were of Russian origin and said there’s no danger of data theft since the devices were going to be on a closed loop Ministry network.
该部最初否认这些摄像头来自俄罗斯,并表示不存在数据被盗的危险,因为这些设备将接入内政部的闭环网络。

According to an NBU technical report, besides the backdoor system, the cameras also contain several security flaws. They have a crucial SecureBoot security feature that’s turned off so the firmware origin is never enforced, the web management portal contains multiple vulnerabilities, and the cameras expose live streams to anyone without a password and who knows their broadcasting IP.
根据 NBU 的一份技术报告,除了后门系统外,这些摄像头还存在多个安全漏洞。它们的关键 SecureBoot 安全功能被关闭,因此固件来源从未被强制验证;网页管理门户包含多个漏洞;而且摄像头会向任何无需密码且知道其广播 IP 的人暴露实时视频流。

Interior Ministry officials paused the camera deployment after the NBU report and said it would order an additional assessment from an independent auditor to confirm the findings.
内政部官员在 NBU 报告发布后暂停了摄像头的部署,并表示将委托独立审计机构进行额外评估以确认这些发现。

Some similar devices are also allegedly installed in Croatia and maybe some other countries in Eastern Europe.
据称,克罗地亚以及东欧其他一些国家也安装了一些类似设备。

Nobody should be buying security cameras from Russia, or China for that matter https://t.co/ZiuuZ3ODjQ
任何人都不应该从俄罗斯购买安全摄像头,中国也一样 https://t.co/ZiuuZ3ODjQ

â ChrisO_wiki (@ChrisO_wiki) August 18, 2026
—— ChrisO_wiki (@ChrisO_wiki) 2026年8月18日

Risky Business Podcasts
Risky Business 播客

In this episode of Risky Business Features, James Wilson chats with PortSwiggerâs Director of Research James Kettle about using an LLM to develop genuinely new attack techniques.Â
在本期 Risky Business Features 中,James Wilson 与 PortSwigger 研究总监 James Kettle 探讨了如何使用 LLM 开发真正新颖的攻击技术。

Breaches, hacks, and security incidents
数据泄露、黑客攻击和安全事件

Scammers target UK prime minister: A scammer targeted UK Prime Minister Andy Burnham by posing as White House chief of staff Susie Wiles. Burnham detected the scam himself and the UK embassy notified the White House. Multiple US senators, governors, and executives were also targeted by scammers posing as Wiles last year. The White House blamed the incident on a hacker obtaining a copy of her cellphone contacts. [Politico Europe]
诈骗者盯上英国首相:一名诈骗者冒充白宫幕僚长 Susie Wiles,将目标对准英国首相 Andy Burnham。Burnham 自己识破了骗局,英国大使馆通知了白宫。去年,多名美国参议员、州长和高管也成为冒充 Wiles 的诈骗者的目标。白宫将事件归咎于一名黑客获取了她手机通讯录的副本。[Politico Europe]

Hackers target Ukraine’s ARMA agency: A cyberattack has disrupted the activities of Ukraine’s agency for managing seized Russian assets. The attack took place this week as the agency was preparing to assign a new manager for beverage company IDS Ukraine. Ukraine seized IDS from Alfa-Bank co-founder Mikhail Fridman shortly after Russia’s invasion. The agency didn’t attribute the attack. [RBC // ARMA]
黑客攻击乌克兰 ARMA 机构:一次网络攻击扰乱了乌克兰负责管理被没收俄罗斯资产的机构的活动。攻击发生在本周,当时该机构正准备为饮料公司 IDS Ukraine 任命新经理。乌克兰在俄罗斯入侵后不久从阿尔法银行联合创始人 Mikhail Fridman 手中没收了 IDS。该机构未对攻击进行归因。[RBC // ARMA]

Hack hits Berlin government: A cyberattack has disrupted two major departments in the Berlin city government. The attack took down emails, remote gateways, and internet connections across the transport and urban development departments. IT staff have disconnected the two agencies from the city network to prevent the incident from spreading. [Tagesspiegel // RBB24 // Yahoo Finance!]
黑客攻击柏林政府:一次网络攻击扰乱了柏林市政府的两个主要部门。攻击导致交通和城市发展部门的电子邮件、远程网关和互联网连接中断。IT 工作人员已将这两个机构与城市网络断开,以防止事件蔓延。[Tagesspiegel // RBB24 // Yahoo Finance!]

Breach at genetics testing company: Genetics-testing company Baylor Genetics is notifying users of a security breach that exposed their personal information. The breach took place in June and both patient and employee data was compromised. The company didn’t disclose the number of affected individuals. [Baylor Genetics // CybersecurityDive]
基因检测公司数据泄露:基因检测公司 Baylor Genetics 正在通知用户一起安全漏洞事件,该事件暴露了他们的个人信息。泄露发生在 6 月,患者和员工数据均遭到泄露。该公司未披露受影响人数。[Baylor Genetics // CybersecurityDive]

UT San Antonio breach: The University of Texas at San Antonio has taken its IT systems offline after a security breach over the weekend. Classes for the new school year are expected to start on Wednesday as scheduled. The university has extended tuition payment deadlines and plans to reset all user account passwords once systems are online. [UT San Antonio // The Record]
德克萨斯大学圣安东尼奥分校数据泄露:德克萨斯大学圣安东尼奥分校在周末发生安全漏洞后已将其 IT 系统下线。新学年课程预计将于周三按计划开始。该大学已延长学费缴纳期限,并计划在系统恢复上线后重置所有用户账户密码。[UT San Antonio // The Record]

Ransomware disables hospital doors, HAVC: A ransomware attack has disabled access doors, heating, ventilation, and air conditioning at Winnipeg’s largest hospital. The Winnipeg Health Sciences Centre increased onsite security while the access card system is still down. The hospital says patien
勒索软件导致医院门禁和暖通空调系统瘫痪:一次勒索软件攻击导致温尼伯最大医院的门禁、供暖、通风和空调系统瘫痪。温尼伯健康科学中心在门禁卡系统仍处于瘫痪状态期间加强了现场安保。医院表示,患……