安全客September 21, 2026🇨🇳Translated from Chinese

China Public Security Ministry Warns IoT Operators: Default Passwords on Devices Like Bus Stop Displays Violate Cybersecurity Law Even Without Major Incidents

A public bus stop electronic display in Wuhu, Anhui became a compromised botnet node after its router retained factory-default credentials and exposed administrative services. Local police traced anomalous traffic to the device in April 2026 and confirmed it had been recruited by malware without causing further damage.

Case Details: Default Credentials and Open Ports

The router used unchanged admin/admin credentials, kept its web management interface, SSH port, and NAT traversal functions enabled. These settings allowed remote attackers to gain control with minimal effort, turning the station display into a remotely operated 肉鸡 (zombie). Authorities ordered the operator to remediate but noted that the absence of severe consequences did not exempt the entity from legal responsibility.

The case formed part of the Ministry of Public Security’s Hu Wang 2026 campaign, which publicly listed ten representative incidents. Researcher Zhi Zhenfeng from the Chinese Academy of Social Sciences emphasized that the Cybersecurity Law requires network operators to adopt technical measures against intrusion and to maintain logs for no less than six months; failure to change defaults or restrict ports already breaches these obligations.

RCtea Botnet Activity and National Scale

The National Internet Emergency Center had previously warned that the RCtea botnet, active since late 2025, specifically targets routers and cameras via Telnet brute-force of weak passwords. Between 20 and 25 January 2026 alone, 9,827 Chinese devices were confirmed infected. Similar enforcement actions followed in Qinghai Guoluo and Nanchong, where entities received administrative warnings after refusing to fix persistent weak-password issues.

International Precedents and Root Causes

Comparable incidents abroad include compromised bus displays in Yeosu, South Korea, and Curitiba, Brazil, where attackers replaced scheduled information with inappropriate content. Analysts attribute the pattern to procurement practices that omit security budgets, lack of skilled personnel at operating agencies, and unclear responsibility between contractors and owners.

Recommended Actions for Operators, Regulators, and Vendors

  • Operators must change default passwords immediately, disable unnecessary remote ports, enforce network segmentation, retain logs, and establish monitoring procedures.
  • Regulators should incorporate IoT assets into routine inspections and pursue administrative penalties for non-compliance.
  • Manufacturers should enforce mandatory password changes on first login and disable high-risk remote functions by default.

The campaign ultimately identified more than 7,900 network and data security risks and prompted remediation of 38,000 vulnerabilities while handling 38,000 administrative cases for failure to fulfill security obligations. The Ministry concluded that every networked device, regardless of size, represents a potential entry point that must be inventoried and hardened.

Related articles

HabrPolicy & Regulation

Alfa-Bank Balances Cloud Trust and Zero Trust Models During Migration to Yandex Cloud

Alfa-Bank's head of container and cloud security, Sasha Chertok, detailed how the bank migrated regulated workloads to Yandex Cloud while preserving existing Zero Trust controls. The organization mapped on-premises network segmentation, Active Directory authentication, and firewall policies directly onto Yandex Cloud resources using interconnect links secured with GOST encryption. Responsibility for managed services is shared under a Cloud Trust model, yet the bank retains oversight through Terraform-managed Security Groups, custom CSPM checks, and internal CI/CD gates. User access continues to authenticate via on-premises Active Directory and KeyCloak federations, while authorization leverages granular Yandex Cloud IAM roles. Logging and detection rely on a combination of Yandex Cloud Audit Trail, Cloud Logging, and the YCDR service to compensate for incomplete control-plane visibility. The resulting hybrid architecture now supports 1,500 virtual machines, 100 managed services, and 1,000 identities across multiple environments without disrupting established security processes.

HabrPolicy & Regulation

EnvSpec Naming Standard Introduces Strict Six-Environment Hierarchy for Zero Trust Infrastructure

The EnvSpec Naming 1.0.0 standard proposes replacing ad-hoc hostnames with a strict hierarchical naming system based on environment, perimeter, system, slot and node. It defines exactly six environments—dev, test, stage, prod, infrastructure and workplace—and treats any test or pilot system processing real data as prod. The model projects names into SPIFFE IDs, Kubernetes namespaces, cloud projects and mandatory tags for automated policy enforcement. Rules prohibit direct communication between different linear environments and require all access from workplace devices through dedicated gateways. The standard is published under CC BY-SA 4.0 and includes machine-checkable criteria for compliance.

AntiMalwarePolicy & Regulation

Russian Woman Fined 30,000 Rubles and Loses iPhone 11 for Posting AI-Generated Bear Photo

A resident of Duldurga village in Zabaykalsky Krai was fined 30,000 rubles under part 9 of article 13.15 of the Russian Code of Administrative Offenses for publishing an AI-generated image of a bear presented as authentic. The court also ordered confiscation of her iPhone 11 as the instrument of the administrative violation. The woman knew the photograph was fake before posting it, yet the image spread widely online and was even shared by a local Ministry of Natural Resources channel on 10 September. Local authorities used the case to warn residents that publishing neural-network-generated fake images carries real legal consequences. The incident highlights ongoing enforcement of Russian legislation against the distribution of knowingly false socially significant information under the guise of credible reports. Meanwhile, wildlife specialists continue to investigate separate reports of actual bears near populated areas in the region.

HabrPolicy & Regulation

Inserting Contracts into ChatGPT Risks Major Fines Under Russia's 152-FZ Personal Data Law

A detailed analysis examines the legal consequences of uploading contracts containing personal data into foreign AI services such as ChatGPT under Russian Federal Law 152-FZ. The article clarifies that even standard supply agreements include names, positions, passport details, INN numbers, phones and emails that qualify as personal data. It breaks down applicable administrative penalties from Article 13.11 of the Code of Administrative Offenses, including 150-300 thousand rubles for processing without a proper legal basis and separate fines for failing to notify Roskomnadzor. Cross-border transfer rules under Article 12 require a dedicated notification to the regulator before sending data to services hosted in the United States or European Union. The piece also reviews recent court practice, including a Moscow district court ruling that treated uploading commercial information to DeepSeek as disclosure of trade secrets. No criminal liability under Article 272.1 of the Criminal Code applies to ordinary business use, yet the absence of a data processing agreement with OpenAI or similar providers creates ongoing compliance exposure.