惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Fortinet All Blogs
Last Week in AI
Last Week in AI
IT之家
IT之家
A
About on SuperTechFans
M
MIT News - Artificial intelligence
Y
Y Combinator Blog
T
The Blog of Author Tim Ferriss
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 三生石上(FineUI控件)
博客园 - 【当耐特】
V
Visual Studio Blog
Microsoft Security Blog
Microsoft Security Blog
博客园_首页
aimingoo的专栏
aimingoo的专栏
The Cloudflare Blog
Vercel News
Vercel News
博客园 - Franky
有赞技术团队
有赞技术团队
B
Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
GbyAI
GbyAI
量子位
云风的 BLOG
云风的 BLOG
T
Tailwind CSS Blog

GRAHAM CLULEY

Smashing Security podcast #485: These researchers got drunk to hack an LG TV Former AT&T store worker jailed after moonlighting as a SIM-swap gang's inside man 'Anne Hathaway' admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars Smashing Security podcast #484: How websites are tracking you with silence CRPx0 ransomware: what you need to know The US military just turned off ad tracking on its phones. Maybe you should too How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts Smashing Security podcast #483: This AI helps thieves steal your iPhone Revolut scam steals £180,000 from Jersey residents in just four weeks Shai-Hulud hackers: two men charged over TeamPCP's global supply chain crime spree that hit OpenAI, and thousands more US Navy tells sailors and their families: scrub your social media, enemies are watching Smashing Security podcast #482: This hacker leaked GTA 6 - and launched their own cryptocurrency Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials Gunra ransomware: what you need to know Smashing Security podcast #481: Never say this to a robot dog Prison for data analyst who tried to extort $2.5 million from his employer An "invisible" car? Researcher uses machine learning to hide vehicles from Flock cameras Smashing Security podcast #480: This is the AI service you should never sign up to Meta's Ray-Bans are being banned from pubs, restaurants, and theatres Beware cut-price AI services that read your every word Apple's bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Fake IRS letters target cryptocurrency holders The $5 million threat: AI Is supercharging phishing attacks North Korea's elite hackers turned on their own government — and got caught Smashing Security podcast #478: This job interview could destroy your company OpenAI's AI "goes rogue" and hacks Hugging Face: what you need to know Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker Ukraine warns fake CAPTCHAs are being used to make you hack yourself
Denver's crosswalks hacked to broadcast anti-Trump messages
2026-03-20 · via GRAHAM CLULEY

Pedestrians crossing a street in Denver, Colorado, got rather more than they bargained for last weekend, when the audio signals at two crosswalks began broadcasting a political message alongside their usual walking instructions.

"The walk signal is on, f*** Trump. The walk signal is on, Trump murders children"

That was the rather blunt message being played in a robotic voice to surprised pedestrians as they walked down East Colfax Avenue, Denver, according to numerous posts shared across social media.

It's a tale that should sound familiar to regular readers of Hot for Security. For instance, just last year we reported on a very similar wave of crosswalk hacking, n which pedestrians in Palo Alto, Menlo Park, and Seattle were startled to hear deepfake audio impersonating tech giants Elon Musk, Mark Zuckerberg, and Jeff Bezos.

A security researcher had previously demonstrated that it was trivially easy to reconfigure the audio used by crosswalk systems made by Polara, because installers had not bothered to change the default password.

Fast forward to 2026, and local media reports suggest that the newly-installed crosswalk units in Denver were similarly accessed due to their use of factory-default credentials.

In other words, here we go again. Same vulnerability, different crosswalk.

The affected crosswalks in Denver - intended to help people with visual impairments safely cross navigate intersections - had been recently installed at the junctions of East Colfax Avenue with North Pearl Street and North Washington Street, according to Nancy Kuhn, Communications Director at Denver's Department of Transportation and Infrastructure.

She told The Denver Post that the devices were not yet supposed to be operational, but had recently been turned on while still using their factory settings.

Passwords on the affected crosswalks have since been changed, and police say that they are investigating the matter.

While it's easy to discount such attacks as mischievous pranks, there is a serious impact to hacks like this. After all, the audio of a crosswalk is something that people who are blind or are visually impaired depend upon for their safety. Tampering with them - whatever the political motivation - introduces a hazard, and cash-strapped city authorities are forced to spend time and money fixing them.

None of which, of course, ignores the fact that the underlying vulnerability is entirely preventable. Default passwords have plagued all manner of technology, including crosswalks and other roadside infrastructure in the past.