Gen. partnerAlgotech

Thousands of cameras online, data leak at Booking.com and record fraud in the Czech Republic

Security researcher Michal Frýba's analysis shows that thousands of cameras around the world are publicly accessible online. This is not hacking, but misconfigured devices that are directly exposed to the internet.

|
April 20, 2026

Publicly accessible cameras are not an exception

Security researcher Michal Frýba's analysis shows that thousands of cameras around the world are publicly accessible online. This is not hacking, but misconfigured devices that are directly exposed to the internet.

The data come from the Shodan service, which indexes devices connected to the internet. In some cases, images from places that definitely should not be public appear – from offices to private homes.

Booking.com and the risk that comes after an attack

Booking.com confirmed an incident in which attackers may have gained access to users' reservation data. These are not payment details, but a combination of information that enables very convincing fraudulent messages.

This is where an important shift becomes clear. A data leak is often not the end, but the beginning. Attackers use the obtained data for targeted phishing that fits into the victim's real context.

Cyber scams in the Czech Republic are breaking records

The Police of the Czech Republic report a record increase in cybercrime. March was the worst month in history and the number of cases is rising sharply.

Vishing plays the dominant role — phone scams in which attackers pretend to be bankers or police officers. It's not a technical attack, but manipulation which, combined with pressure and stress, leads to very high damages.

Attack via the supply chain

Cloud platform Vercel is dealing with an incident that began with the compromise of a third-party tool. The attacker then gained access to the company's internal systems.

This is a typical example of a supply chain attack, where the attacker does not get into the company directly, but through its suppliers or the tools it uses.

Critical vulnerabilities in Cisco

Cisco released patches for several critical flaws in the Webex and Identity Services Engine platforms. Some of them allow bypassing authentication or executing code on a compromised device.

Although there is no evidence of active exploitation yet, it's a reminder that identity and access systems are among the most sensitive parts of infrastructure.

What this means

A common denominator of all these events is a simple thing. The weakest link is not the technology, but people and configuration.

And that's why today it's not enough to just monitor threats. You need to understand them.

Loading comments...

Stay in the loop

Subscribe to our newsletter and get the latest cybersecurity news delivered straight to your inbox.

Your data is safe. You can unsubscribe from the newsletter at any time.