惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Announcements
Recent Announcements
爱范儿
爱范儿
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
宝玉的分享
宝玉的分享
T
Tailwind CSS Blog
博客园_首页
IT之家
IT之家
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 三生石上(FineUI控件)
有赞技术团队
有赞技术团队
大猫的无限游戏
大猫的无限游戏
雷峰网
雷峰网
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 司徒正美
WordPress大学
WordPress大学
Last Week in AI
Last Week in AI
人人都是产品经理
人人都是产品经理
Jina AI
Jina AI
月光博客
月光博客
小众软件
小众软件
S
SegmentFault 最新的问题
量子位
阮一峰的网络日志
阮一峰的网络日志
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知

GRAHAM CLULEY

Former AT&T store worker jailed after moonlighting as a SIM-swap gang's inside man 'Anne Hathaway' admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars Smashing Security podcast #484: How websites are tracking you with silence CRPx0 ransomware: what you need to know The US military just turned off ad tracking on its phones. Maybe you should too How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts Smashing Security podcast #483: This AI helps thieves steal your iPhone Revolut scam steals £180,000 from Jersey residents in just four weeks Shai-Hulud hackers: two men charged over TeamPCP's global supply chain crime spree that hit OpenAI, and thousands more US Navy tells sailors and their families: scrub your social media, enemies are watching Smashing Security podcast #482: This hacker leaked GTA 6 - and launched their own cryptocurrency Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials Gunra ransomware: what you need to know Smashing Security podcast #481: Never say this to a robot dog Prison for data analyst who tried to extort $2.5 million from his employer An "invisible" car? Researcher uses machine learning to hide vehicles from Flock cameras Smashing Security podcast #480: This is the AI service you should never sign up to Meta's Ray-Bans are being banned from pubs, restaurants, and theatres Beware cut-price AI services that read your every word Apple's bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Fake IRS letters target cryptocurrency holders The $5 million threat: AI Is supercharging phishing attacks North Korea's elite hackers turned on their own government — and got caught Smashing Security podcast #478: This job interview could destroy your company OpenAI's AI "goes rogue" and hacks Hugging Face: what you need to know Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker Ukraine warns fake CAPTCHAs are being used to make you hack yourself Google's Gemini lets strangers send messages from your locked Android phone
Denver's crosswalks hacked to broadcast anti-Trump messages
2026-03-20 · via GRAHAM CLULEY

Pedestrians crossing a street in Denver, Colorado, got rather more than they bargained for last weekend, when the audio signals at two crosswalks began broadcasting a political message alongside their usual walking instructions.

"The walk signal is on, f*** Trump. The walk signal is on, Trump murders children"

That was the rather blunt message being played in a robotic voice to surprised pedestrians as they walked down East Colfax Avenue, Denver, according to numerous posts shared across social media.

It's a tale that should sound familiar to regular readers of Hot for Security. For instance, just last year we reported on a very similar wave of crosswalk hacking, n which pedestrians in Palo Alto, Menlo Park, and Seattle were startled to hear deepfake audio impersonating tech giants Elon Musk, Mark Zuckerberg, and Jeff Bezos.

A security researcher had previously demonstrated that it was trivially easy to reconfigure the audio used by crosswalk systems made by Polara, because installers had not bothered to change the default password.

Fast forward to 2026, and local media reports suggest that the newly-installed crosswalk units in Denver were similarly accessed due to their use of factory-default credentials.

In other words, here we go again. Same vulnerability, different crosswalk.

The affected crosswalks in Denver - intended to help people with visual impairments safely cross navigate intersections - had been recently installed at the junctions of East Colfax Avenue with North Pearl Street and North Washington Street, according to Nancy Kuhn, Communications Director at Denver's Department of Transportation and Infrastructure.

She told The Denver Post that the devices were not yet supposed to be operational, but had recently been turned on while still using their factory settings.

Passwords on the affected crosswalks have since been changed, and police say that they are investigating the matter.

While it's easy to discount such attacks as mischievous pranks, there is a serious impact to hacks like this. After all, the audio of a crosswalk is something that people who are blind or are visually impaired depend upon for their safety. Tampering with them - whatever the political motivation - introduces a hazard, and cash-strapped city authorities are forced to spend time and money fixing them.

None of which, of course, ignores the fact that the underlying vulnerability is entirely preventable. Default passwords have plagued all manner of technology, including crosswalks and other roadside infrastructure in the past.