LogoLogo

Podcasts

Newsletters

Videos

Catalog

People

About

Search

Risky Bulletin Newsletter

August 19, 2026

Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras

Written by

Catalin Cimpanu
Catalin Cimpanu

News Editor

This newsletter is brought to you by Socket Security. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.

Slovakia's national security service NBU has issued a security alert against the use of NERO R-ONE high-speed traffic cameras.

The agency says the cameras contain a backdoor mechanism that will execute malicious code received via an SMS from a list of hardcoded Russian phone numbers.

The NBU started an investigation into the devices after multiple reports in Slovak media that the cameras were bought with a no-bid direct contract from a Cyprus shell company with fake certifications.

According to the NBU, the cameras are a rebranded version of a Russian traffic camera model named CORDON PRO.M, produced by St. Petersburg-based Russian firm Semicon.

via NBU

The cameras were bought as part of a €30 million EU-funded project to rebuild the country's national traffic monitoring system.

The Interior Ministry has allegedly bought and installed 279 cameras on selected roads across Slovakia.

The Ministry initially denied that the cameras were of Russian origin and said there's no danger of data theft since the devices were going to be on a closed loop Ministry network.

According to an NBU technical report, besides the backdoor system, the cameras are also very insecure. They have a crucial SecureBoot security feature turned off so the firmware origin is never enforced, the web management portal contains multiple vulnerabilities, and the cameras expose live streams to anyone without a password and who knows their broadcasting IP.

Interior Ministry officials paused the camera deployment after the NBU report and said it would order an additional assessment from an independent auditor to confirm the findings.

Source

Nobody should be buying security cameras from Russia, or China for that matter https://t.co/ZiuuZ3ODjQ

— ChrisO_wiki (@ChrisO_wiki) August 18, 2026

Risky Business Podcasts

In this episode of Risky Business Features, James Wilson chats with PortSwigger’s Director of Research James Kettle about using an LLM to develop genuinely new attack techniques. 


Breaches, hacks, and security incidents

Scammers target UK prime minister: A scammer targeted UK Prime Minister Andy Burnham by posing as White House chief of staff Susie Wiles. Burnham detected the scam himself and the UK embassy notified the White House. Multiple US senators, governors, and executives were also targeted by scammers posing as Wiles last year. The White House blamed the incident on a hacker obtaining a copy of her cellphone contacts. [Politico Europe]

Hackers target Ukraine's ARMA agency: A cyberattack has disrupted the activities of Ukraine's agency for managing seized Russian assets. The attack took place this week as the agency was preparing to assign a new manager for beverage company IDS Ukraine. Ukraine seized IDS from Alfa-Bank co-founder Mikhail Fridman shortly after Russia's invasion. The agency didn't attribute the attack. [RBC // ARMA]

Hack hits Berlin government: A cyberattack has disrupted two major departments in the Berlin city government. The attack took down emails, remote gateways, and internet connections across the transport and urban development departments. IT staff have disconnected the two agencies from the city network to prevent the incident from spreading. [Tagesspiegel // RBB24 // Yahoo Finance!]

Breach at genetics testing company: Genetics-testing company Baylor Genetics is notifying users of a security breach that exposed their personal information. The breach took place in June and both patient and employee data was compromised. The company didn't disclose the number of affected individuals. [Baylor Genetics // CybersecurityDive]

UT San Antonio breach: The University of Texas at San Antonio has taken its IT systems offline after a security breach over the weekend. Classes for the new school year are expected to start on Wednesday as scheduled. The university has extended tuition payment deadlines and plans to reset all user account passwords once systems are online. [UT San Antonio // The Record]

Ransomware disables hospital doors, HAVC: A ransomware attack has disabled access doors, heating, ventilation, and air conditioning at Winnipeg's largest hospital. The Winnipeg Health Sciences Centre increased onsite security while the access card system is still down. The hospital says patient care and clinical operations are not impacted. [CBC // The Winnipeg Free Press] [h/t Alex Rudolph]

BlueSky and GitHub hit by Iranian DDoS attacks: An Iranian hacktivist group took down BlueSky and GitHub with DDoS attacks on Sunday and Monday, respectively. The attacks caused prolonged outages at both companies. A group known as the 313 Team took credit for the attacks. The hackers were also behind another wave of DDoS attack in April. [Telegram // Telegram]

We apologize for yesterday’s service problems. Bluesky experienced a DDoS attack—a flood of junk traffic meant to knock servers offline—over a period of 24 hours. We have upgraded our defenses in response, and we continue to monitor the situation. Follow @status.bsky.app for any updates.

— Bluesky (@bsky.app) August 18, 2026 at 12:27 AM

SafePal breach: Hackers have stolen the personal information of 40,000 customers of hardware crypto-wallet provider SafePal. The incident impacted all customers who placed orders of SafePal wallets between March 2, 2025, and April 11, 2026. SafePal says no seed phrases or private keys are impacted. The stolen data is still dangerous because it could enable wrench attacks on wallet holders. [SafePal // SecurityWeek]

Bits of Gold breach: Hackers have stolen the data of 250,000 customers of Bits of Gold, Israel's largest cryptocurrency exchange. The company notified customers of the hack over the weekend. It said the data was stolen from an external analytics service provider. It didn't say what type of data was stolen. [CTech]

TheHatman dumps employee data for a dozen companies: A threat actor is selling the employee data of almost a dozen Fortune 500 companies. The hacker, who goes by TheHatman, claims the data was stolen by using stolen credentials to access each victim's Azure environments. The hacker claims they breached McDonalds, Vodafone, Gap, and the Intercontinental and Wyndham hotel chains. [HudsonRock]

AI, general tech, and privacy

Windows to drop WMIC: The current Windows 11 installation packages and Insider Builds do not ship with the Windows Management Instrumentation Command-line (WMIC) feature anymore. Microsoft deprecated the toolkit a few years ago after it saw massive abuse. [Microsoft // WindowsLatest]

Firefox 154: Mozilla has released Firefox 154. New features and security fixes are included. The biggest feature in this release is support for GeForce NOW, NVIDIA's cloud gaming platform. [Firefox]

Firefox for iOS gets an ad blocker: Mozilla has added an ad blocker to Firefox on iOS. It is turned off by default. [Mozilla]

Government, politics, and policy

Russian things: A Russian court has forced two Telegram channel owners to remove posts blaming the country's internet watchdog for causing an outage of the country's banking system as part of an attempt to block VPN protocols. This is funny to me because they didn't fine Natalya Kaspersky, one of the Kaspersky co-founders, for basically saying the same thing in an official manner and to more mainstream Russian news outlets. Alas, Russia, a two-tiered society! [Caution News on Telegram]

Sponsor section

In this Risky Business sponsor interview, Casey Ellis chats with Socket founder Feross Aboukhadijeh about npm 12’s move to disable install scripts by default.

Arrests, cybercrime, and threat intel

French cops used public exploit to hack EncroChat: French law enforcement used a public exploit hosted on GitHub to hack encrypted phone network EncroChat in 2020. The exploit was for the Bad Binder Android vulnerability and had been shared online a few months before. EncroChat discovered the hacks after French cops deployed a second exploit that failed. [ComputerWeekly // Bad Binder exploit on GitHub // Bad Binder write-up]

Source

SMS blaster arrested in Malaysia: Malaysian authorities have arrested a 65-year-old suspect for driving around with an SMS blaster in his car. The suspect was detained driving around the border crossing between Johor Bahru and Singapore. He is the second suspect arrested this month in Johor Bahru for SMS blasting. [CommsRisk]

LockerGoga dev on trial in Switzerland: Swiss prosecutors are seeking a 12-year prison sentence for a Ukrainian man linked to ransomware attacks on local companies. Officials claim the suspect was a coder for the LockerGoga, MegaCortex and Nefilim ransomware groups. The suspect is pleading not guilty. He claims he was working as a consultant for a cybersecurity firm when he was detained and the ransomware source code found on his devices. [Watson // The Record]

Ransomware affiliate poses as data recovery firm: A ransomware affiliate is posing as a data recovery firm named Ransom Busters LTD. According to GuidePoint Security, the group has reached out to multiple companies and offered to delete their data from ransomware servers for a fee between $20,000 and $60,000. The group has reached out to victims even before breaches were made public. GuidePoint believes the group has signed up as an affiliate on different Ransomware-as-a-Service platforms to see hacked companies and reach out in advance. [GuidePoint Security]

Operation CameraSwarm: A threat actor has hacked more than 14,500 Dahua security cameras across Ukraine and Russia. Researchers at Hunt Intelligence discovered the botnet after the hacker left an open directory on their server infrastructure. According to files recovered from the server, the hacker exploited old vulnerabilities but also a secret hardcoded account in some of the devices. [Hunt Intelligence]

StopAndProtect profile: Security firm Check Point has published a profile on StopAndProtect, a new e-crime operation using thousands of hacked WordPress sites to redirect users to malware downloads and then store stolen creds. [Check Point]

FUXA scanning: Threat actors are scanning for FUXA SCADA devices in an attempt to exploit CVE-2026-25895, an unauthenticated path traversal that can let hackers rewrite local files. [Caitlin Condon on LinkedIn]

StubMaker RubyGems campaign: The OSM team has spotted 16 malicious RubyGems packages typosquatting more popular packages that spread a Windows infostealer to whoever installs them. [OpenSourceMalware]

Malware technical reports

DragonDoll Android spyware: Russian security firm Positive Technologies has discovered a new Android spyware strain. Named DragonDoll, the spyware is spread using fake Chrome update packages and focuses on stealing data from instant messengers. [Positive Technologies // Archived]

GoldDigger Android trojan: IBM's Trusteer team has published a technical analysis of GoldDigger, an Android banking trojan active since 2023. [IBM]

C2Looper backdoor: In July 2026, researchers identified C2Looper, a new malware family likely used in ransomware attacks to establish a foothold for lateral movement. [Zscaler]

TWINLOOT: Ontinue researchers have discovered TWINLOOT, a Python-coded malware framework that hosts its entire command-and-control infrastructure inside trusted Microsoft services such as Azure, M365, and SharePoint. [Ontinue]

MacSync Stealer: Microsoft has released a technical report on MacSync Stealer, a recent infostealer targeting the macOS ecosystem. [Microsoft]

WordlistLoader: Gen Threat Labs has identified WordlistLoader, a new loader used to deliver Amatera Stealer via ClearFake campaigns. [Gen Digital]

Shadow HVNC and Shadow Loader: Security researchers have reverse-engineered Shadow HVNC and Shadow Loader, two malware families advertised online by a developer known as RemoteX. [Malbear Labs]

ValleyRAT: Despite some arrests this year, the SilverFox group is still active and spreading its ValleyRAT malware. [Forcepoint]

AZALEA RAT: And speaking of RATs, Point Wild looks at the distribution chains of the AZALEA RAT, a new RAT advertised online as AzaleaControl. [Point Wild]

Medusa ransomware: CISA has updated its advisory on the Medusa ransomware with new TTPs. The agency says the group has continued to be active and made hundreds of new victims. [CISA]

Mirage2FA: ANY.RUN's security team looks at a new 2FA-intercepting phishing service named Mirage2FA. The service seems to be geared towards M365 campaigns primarily. [ANY.RUN]

Sponsor section

In this Soap Box edition of the Risky Business podcast Patrick Gray chats with Socket founder Feross Aboukhadijeh about how to measure the reachability of vulnerabilities in applications. It's great to know there's a CVE in a library you're using, but it's even better if you can say whether or not that vulnerability actually impacts your application. 

APTs, cyber-espionage, and info-ops

France investigates Russian disinfo ops: French authorities have launched an investigation into suspected Russian disinformation campaigns targeting the country's pro-EU politicians. The campaigns targeted possible presidential candidates Gabriel Attal and Edouard Philippe as soon as they showed interest in next year's election. Open-source reporting has linked the campaigns to a Russian disinformation group known as Matryoshka and Storm-1516. [FranceInfo]

Operation QUICSILVER: A China threat actor has been targeting Myanmar diplomats via an VHD-delivered Go backdoor named QUICAgent. [Seqrite]

Goffee replaces image files: The Goffee cyber-espionage group has maintained a foothold inside hacked organizations by altering installation images for corporate apps. In a campaign targeting Russian companies, the group has modified 7-Zip and Git installers. [F6]

Core Werewolf's CoreRAT: A highly sophisticated APT group named Core Werewolf has continued its operations targeting Russian orgs with a new remote access trojan named CoreRAT. [BI.ZONE]

Russia and US hold hands in Alberta info-ops: The US and Russia appear to have joined hands in promoting the Alberta separatist movement in Canada. [The Globe and Mail]

"The first data from a study that began last month indicate Russian content farms have been pushing pro-separatist content into online communities and using Canadians to “launder” those messages by sharing such material on their social media feeds, the researchers said. The U.S. activity, on the other hand, is more overt, with prominent American influencers, podcasts and websites openly promoting Alberta separation, said Brian McQuinn, co-director of the Centre for Artificial Intelligence, Data, and Conflict at the University of Regina."

CopyCop (Storm-1516) in Armenia: Russian disinfo group CopyCop ran a disinformation campaign trying to sabotage the construction of a shared US-Armenian AI data center in Hrazdan. [Recorded Future]

PurpleDelta: Recorded Future has identified 22 new personas operated by PurpleDelta, the name the company assigns to North Korea's remote IT worker scheme. Also this week, Bridewell published a guide on how to defend against these groups. [Recorded Future // Bridewell]

Iranian phishing ops target Israeli journalists: Iranian state hackers have intensified spear-phishing attacks targeting Israeli journalists. The country's intelligence and cybersecurity agencies have sent out a security alert about the attacks last week. The agencies say hackers are seeking to obtain private information from journalists reporting on political and national security. [Ynet]

US charges more Mabna hackers: The US has unsealed a superseding indictment against 17 Iranian hackers. The suspects are employees of the Mabna Institute, a cyber contractor for Iran's Islamic Revolutionary Guard Corps. The Justice Department claims Mabna hackers breached universities across the world to steal research and transfer to Iranian counterparts. The superseding charges replace a 2018 indictment that expands the number of suspects from nine to 17. The State Department has also offered a $10 million reward for information that may lead to the arrest of any of the suspects. The Mabna Institute hacking campaigns are tracked by security firms under the codename of Cobalt Dickens. [DOJ 2026 // DOJ 2018 // Rewards for Justice // Sophos]

Vulnerabilities, security research, and bug bounty

Security updates: Apple, Dell, Edge, Firefox, GitLab, Oracle, Tenable, Tor Browser.

AI agent introduces bug in Snowflake's production: Security firm Wiz has spotted an AI coding agent autofixing a bug but introducing a vulnerability in cloud provider Snowflake's production systems. [Wiz]

Microsoft delays Exchange updates due to influx of AI bugs: Microsoft has delayed a major update for Exchange Subscription Edition servers due to an influx of AI-discovered vulnerabilities. The update was supposed to go live at the end of June. Microsoft says it did not want to release its biannual feature update only to release multiple batches of security fixes right after. The company plans to wait to fix all security bugs before releasing the Exchange SE H1 Cumulative Update. Microsoft says employees discovered the security flaws as part of an internal push to use AI tools for bug discovery. [Microsoft]

KEV update: CISA has updated its KEV database with four vulnerabilities that are currently exploited in the wild. All are 2026 bugs, such as a recent Apple macOS ScreenShare bug, a Microsoft IKE one, a SharePoint one, and a VMware vCenter path traversal.

Infosec industry

Acquisition news: Tech giant Fortinet has acquired AI security startup Virtue AI, which specializes in AI runtime protection, automated AI validation, and security for autonomous AI systems. [Fortinet]

Threat/trend reports: Beazley Security, Black Kite, Bridewell, Cyberproof, Ecosyste.ms, JPMorgan, MinterEllison, and Onyxia have recently published reports and summaries covering various emerging threats and industry trends.

Risky Business podcasts

In this edition of Between Two Nerds, Tom Uren and The Grugq discuss The Offense Death Cycle paper looking at how to take advantage of a defender's ability to control a network to discover intruders.

Recent Newsletters

  • Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras
  • Risky Bulletin: The EU publishes its upcoming cybersecurity standards
  • Risky Bulletin: White House lets private companies carry out offensive cyber ops
  • Srsly Risky Biz: Data Theft Extortion Is Booming! Hooray!
  • Risky Bulletin: Russian hackers adopt the fake job interview tactics

Recent Videos

  • James Kettle on inventing new attack techniques with LLMs
  • Between Two Nerds: The eye of Sauron
  • Soap Box: Zero Trust(ish) Networks
  • Srsly Risky Biz: Data extortion is booming. Hooray!
  • Risky Business (848): OpenAI comes clean

Recent Podcasts

  • Risky Bulletin: Slovakia finds Russian backdoors on its speed cameras
  • Risky Business #849 -- Trump will unleash contractors on cybercriminals
  • Between Two Nerds: The eye of Sauron
  • James Kettle on inventing new attack techniques with LLMs
  • Risky Bulletin: The EU publishes its upcoming cybersecurity standards
Risky Business Media

Risky Business

  • Home
  • Podcasts
  • Newsletters
  • Video
  • Sitemap

Risky Business Media

  • About
  • People
  • Advertising
  • Sponsor Enquiries: sales@risky.biz

Risky Connections

  • Risky Business on Apple Podcasts
  • Risky Business on Spotify
  • Risky Bulletin on Apple Podcasts
  • Risky Bulletin on Spotify
  • Risky Business Features on Apple Podcasts
  • Risky Business Features on Spotify
  • Risky Business Stories on Apple Podcasts
  • Risky Business Stories on Spotify
  • YouTube
  • LinkedIn

Risky Contacts

Risky Business Media Pty Ltd
PO Box 774
Byron Bay NSW 2481
General Email: editorial@risky.biz

© Risky Business Media 2007–2026. All rights reserved.
ABN 73 618 465 517