In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia. [...]

A campaign dubbed "CameraSwarm" compromised over 14,500 Dahua IP cameras, primarily in Ukraine and Russia, over a 35-day period between June 17 and July 22. Threat intelligence company Hunt.io discovered the operation after finding an unprotected HTTP server containing 407 MB of data, including source code, logs, credentials, and captured camera images.
The attackers employed three distinct methods to compromise devices. The most prevalent method involved a brute-forcing system that scanned TCP port 37777, leading to the compromise of cameras at 12,324 unique IP addresses. This system captured snapshots, sent results to Telegram, and exported them for Dahua's SMART PSS platform.
Another method exploited CVE-2021-33044 and CVE-2021-33045 using a tool called "p2pwn." This resulted in the installation of a persistent backdoor account, also named "p2pwn" with the password "p2password," on 1,923 cameras. This backdoor account is designed to survive password changes and, on most firmware versions, factory resets.
The third attack vector was a cloud-relay attack, which targeted 283 cameras located behind NAT. This method leveraged only serial numbers and SDK credentials embedded in Dahua applications. Data indicated that 89.4% of live serial numbers exposed an access channel without requiring authentication. The attack toolkit's recovery code generation mechanism utilized the camera's serial number, enabling the operator to obtain new codes through Dahua's standard password recovery process without needing the current administrator password.
Hunt.io's analysis revealed that the scanning operations were global, initially focusing on the Russian address space before expanding to the entire IPv4 range. The operator's primary focus, however, appeared to be on Russian and CIS telecom netblocks. Researchers also noted the presence of Russian comments within modified code sections of repurposed public tools.
On August 10, Hunt.io informed national CERTs and Dahua's PSIRT about the CameraSwarm campaign. Dahua cameras accessible via port 37777 during the June-July period should be considered potentially compromised. Owners are advised to check for the "p2pwn" account and remove it.
However, Hunt.io warns that simply removing the backdoor account will not invalidate recovery codes generated by the toolkit, as these codes remain usable until Dahua modifies the derivation process on its servers. Users are also recommended to disable P2P functionality when it is not needed and to apply Dahua SA-2021-0130 firmware updates, or a later version, to address CVE-2021-33044 and CVE-2021-33045. The researchers also found two unexploited CVE references, CVE-2024-39943 and CVE-2025-31702, in the toolkit.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed