Russian Backdoor Found in Slovak Traffic Cameras, Halting Deployment
Slovakian authorities have halted the rollout of new traffic cameras after discovering Russian-made backdoors and critical software vulnerabilities.

Slovakian cyber authorities have abruptly suspended the deployment of new high-speed traffic cameras following the discovery of significant security flaws, including embedded backdoors. The investigation revealed that the affected devices were rebranded versions of Russian-made hardware, which were then sold into the Slovakian market through a Cyprus-based intermediary company.
The security concerns center on vulnerabilities that could potentially allow unauthorized remote access to live traffic camera feeds. Specifically, reports indicate that these flaws could be exploited via simple SMS messages, a method that bypasses more complex network intrusion techniques and poses an immediate threat to data integrity and privacy.
This discovery has led to an immediate halt in the planned expansion of the country's traffic monitoring infrastructure. The Slovakian National Cyber Security Centre (NCSC) has initiated an investigation to fully assess the extent of the compromise and determine the potential impact on national security and public safety.
While the specific Russian manufacturer has not been publicly named, the involvement of a Cyprus-based firm in the rebranding and distribution process highlights a common tactic used to obscure the origin of hardware and software components. This practice can make it challenging for authorities to trace the supply chain and hold responsible parties accountable.
The implications of this finding extend beyond traffic management. Access to live feeds from traffic cameras could be misused for surveillance, intelligence gathering, or even to aid in criminal activities by providing real-time information on vehicle movements and public spaces.
Authorities are now working to identify all affected devices and determine the best course of action, which may include removal, secure wiping, or replacement of the compromised hardware. The incident underscores the persistent risks associated with relying on hardware from countries with adversarial relationships and the importance of rigorous vetting of all technology components in critical infrastructure.
This situation also raises broader questions about the security of smart city technologies and the global supply chain for surveillance and infrastructure equipment. As more devices become interconnected, the potential for widespread compromise through seemingly isolated components grows, necessitating enhanced vigilance and international cooperation in cybersecurity.