An Argentine researcher managed to access practically the entire technological ecosystem used to manage the public transport of Córdoba: bus and taxi systems, charging platforms, passenger cards, cameras installed in vehicles, personal information and administrative accounts. Some of the tools on display even allowed Shut down or immobilize units remotely.
Ignacio Navarro, a hacker from Córdoba, reported the vulnerabilities to the company responsible and to the CERT nationalwhich coordinates response to computer incidents, and the problems were corrected before they could be exploited by attackers. He presented the details of his work in a talk titled Every ride you take: Hacking a City’s Public Transportationa conference of BSides Las Vegas. The exhibition was part of the so-called Hacker Summer Campthe week in which Las Vegas brings together some of the main cybersecurity events in the world, together with Black Hat y DEF CONthe two main ones.
The investigation showed that a succession of seemingly minor flaws could allow full access to systems used daily by more than 1.5 million people. Navarro found the possibility of sensitive data of thousands of users being leaked and tools capable of interfering with the daily functioning of transportation. Their investigation came in time to prevent possible abuses of the system.
“During the investigation I found a folder with more than 20,000 images of identity documents, salary receipts, residence certificates and schooling certificates,” Navarro explained to Clarion. One of the databases also contained information on more than five million transport cards and around 6,000 administrative accounts.
According to the researcher, the passwords They were insufficiently protected, so it was possible to recover them and enter the systems with administrator privileges.
The case was another example of the fragility of the systems tied to the State: Renaper, Pami, the National Directorate of Migration and other public agencies were hacked during these last years.
From cards to bus cameras
The initial access allowed us to discover new vulnerabilities and advance other connected components. This technique, known as “vulnerability chaining,” consists of combining different errors that separately might seem limited, but together they allow entire systems to be compromised.
Navarro managed to enter management and charging platforms, devices installed within buses and systems linked to taxis. He also accessed the service used to manage the vehicles’ DVRs, the equipment that receives and stores the camera recordings security.
While investigating, he realized that the problem was bigger than he thought: this system controlled more than 1,400 devices distributed in more than ten provinces and allowed access to both the cameras and the stored recordings. Their study also reached government platforms integrated with the transportation ecosystem, both at the provincial and national levels.
“At that moment I decided to stop the investigation and immediately report the problem to both the company and the national CERT,” Navarro said. The company operating the service was kept in reserve for security reasons.
The most serious risk, however, was not only in the exposure of documents or passwords. Among the administrative functions were tools to control vehicles remotely, including options to turn them off or immobilize them.
An attacker could also have altered the operation of transportation cards or interrupted other systems essential for daily operations. “A massive interruption would have generated a chain effect that far exceeds the computer system. Public transportation is an essential service that millions of people use to go to work, study or attend a medical appointment,” the researcher explained, before giving the talk.
According to Navarro, a person with malicious intentions and the same level of access could have caused simultaneous problems in different parts of the country.
This type of investigation by hackers falls within what is known in the field as “offensive” security, that is, testing how secure the systems are and then alerting and correcting them before an attacker exploits them. There is no indication that the vulnerabilities were exploited before being reported.
The odyssey to report the problem in Argentina: critical infrastructure under the magnifying glass
Attacks on critical infrastructure have a separate chapter in the world of cybersecurity. Cyberattacks against oil companies, as happened in 2021 in the United States (Colonial Pipeline) or the best known in the world, Stuxnet (a virus in Iranian nuclear plants) in 2010, show what can be done with a hack to a system and the devastating effects they can have for a society.
For this reason, for Navarro, the case shows that mobility platforms should receive a level of protection similar to that of banks, energy networkshealth services and other sectors considered critical infrastructure.
“Many times we think about the security of banks or large companies, but transportation also supports the daily lives of millions of people,” says Navarro.
The interesting thing, which Navarro pointed out during his presentation, is that many times the problems are not due to a complex or difficult-to-exploit vulnerability, but rather transportation systems are made up of applications, devices, databases and services developed at different times and sometimes by different suppliers. This multiplies the possibility of potential problems: as they grow and begin to connect to new platforms, small design errors can compound and produce much larger consequences.
“As with many systems, the goal is usually to get them working and to market as quickly as possible. Security is left for a later stage or it is incorporated as we go,” he criticized.
The main recommendation, he explains, is to incorporate security controls from the beginning of development and not only after an incident or an audit. Correcting a failure when a platform is already operational is usually more expensive and complex than designing it from the beginning to reduce risks.
It is also essential that companies and public organizations have clear channels to receive reports from researchers. It was difficult for Navarro to receive a response from official entities.
“Many times, the first reaction to a report is to deny it, minimize it or even see the hacker as a problem. Security improves when there is collaboration between those who develop the systems and those who help find their weaknesses in a responsible manner. The objective of both should be the same: protect users and prevent an incident from ending up affecting an essential service for millions of people,” he said.
Navarro is a regular participant on the international security conference circuit. In recent years he has exhibited at events such as DEF CON, H2HC, Troopers, LeHACK, NorthSec, TyphoonCon, Security Fest, SASCON and 8.8, as well as Ekoparty in Argentina.
In 2024, he presented research on vulnerabilities in the security system at that conference. Sacoaone of the best-known video game arcade chains in the country. The flaws allowed access to customer information and imitation of the cards used to play without paying. In that case, he also worked with the company to solve the problems.
BSides Las Vegas: a parallel conference that is already part of the “hacker summer camp”
BSides was born in the United States in 2009 as a more open and community alternative to large corporate cybersecurity events. Its name refers to “side B”: collaborative and non-profit meetings where researchers, students and professionals can present technical work and discuss security problems.
The model was later extended to dozens of cities. While Las Vegas welcomes conferences like Black Hat y DEF CON, BSides Las Vegas serves as one of the main side events of the week.
The conference also had an Argentine edition. In May 2025, BSides arrived in Córdoba for the first time, with a day organized at the National Technological University. The activity brought together 300 in-person attendees, reached 700 registered and included nine technical talks.
A particularity of the conference are the “SkyTalks”talks to which it is not allowed to enter with a cell phone because nothing can be recorded or recorded. Everything that is told in those spaces remains there and, if told or published, cannot be attributed to a specific speaker.
A historical precedent that gave rise to the talks was the case of Michael Lynn: at Black Hat 2005, Cisco and his employer, Internet Security Systems, They tried to prevent it from presenting a serious failure on company routers, had his slides removed from conference materials and sued him when he decided to speak anyway. SkyTalks moved to BSides Las Vegas in 2024.
Clarion He participated in two of these talks this year, to which you even have to enter with masks so as not to reveal your identity.
More than ever, what happens in Vegas stays in Vegas, hacker world edition.
Nastavení DSL routeru TP-Link – TeamCity
استكشف مجموعات موسيقية متنوعة بسهولة من خلال مكتبة أغاني Albumaty
كيف غيّرت المنصات الرقمية أسلوب اكتشاف الموسيقى والاستماع إليها اليوم
Find cooking ideas from Albumaty on Cookpad
Albu maty – Outside
%D9%83%D9%8A%D9%81 %D9%8A%D8%Ba%D9%8A%D9%91%D8%B1 %D8%A7%D9%84%D9%88%D8%B5%D9%88%D9%84 %D8%A7%D9%84%D8%B0%D9%83%D9%8A %D9%84%D9%84%D9%85%D9%88%D8%B3%D9%8A%D9%82%D9%89 %D8%Aa%D8%Ac%D8%B1%D8%A8%D8%A9 %D8%A7%D9%84%D8%A7%D8%B3%D8%Aa%D9%85%D8%A7%D8%B9 %D8%A7%D9%84%D8%B1%D9%82%D9%85%D9%8A%D8%A9 %D8%A7%D9%84%D9%8A%D9%88%D9%85%D9%8A%D8%A9 F0De1Fc49E75
O nás – TeamCity
Ověření rychlosti – TeamCity
Albumaty | Profile
Často kladené otázky – TeamCity
Penzu
كيف تسهّل المنصات الرقمية اكتشاف الموسيقى والاستمتاع بها يوميًا
Sutori
238145267636948835
The profile of Albumaty in AI Art Community & Gallery: Create, Share, Inspire | Fotor
كيف يغيّر الاستماع الرقمي طريقة اكتشاف الموسيقى وتحميلها بسهولة
العنوان: كيف تجعل تجربة اكتشاف الموسيقى أكثر سهولة وتنظيماً في العصر الرقمي
%D9%83%D9%8A%D9%81 %D8%Ba%D9%8A %D8%B1%D8%Aa %D8%A7%D9%84%D9%85%D9%86%D8%B5%D8%A7%D8%Aa %D8%A7%D9%84%D8%B1%D9%82%D9%85%D9%8A%D8%A9 %D8%A3%D8%B3%D9%84%D9%88%D8%A8 %D8%A7%D9%83%D8%Aa%D8%B4%D8%A7%D9%81 %D8%A7%D9%84%D9%85%D9%88%D8%B3%D9%8A%D9%82%D9%89 %D9%88%D8%A7%D9%84%D8%A7%D8%B3%D8%Aa%D9%85%D8%Aa%D8%A7%D8%B9 %D8%A8%D9%87%D8%A7
عنوان: اكتشف أفضل طرق الاستماع إلى الموسيقى وتحميلها بسهولة وأمان اليوم – Albumaty
Albumaty | Profile
اعثر على مقاطعك المفضلة عبر خيارات تحميل الأغاني المتاحة عبر الإنترنت
Albumaty
Albumaty
Albumaty
استمتع بسهولة الوصول إلى أغانيك المفضلة مع Albumaty