LIVE · cybersecurity feed
Live wire
8,539 reasons to rethink how vulnerabilities get patched'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllersNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureCVE-2024-39943 · Operation CameraSwarm Compromised 14,000+ Dahua CamerasCVE-2026-19490 · CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler GatewayA California county wants to hire Tina Peters to help run its electionsThe long tail of Clop’s PTC hack is just beginning to emergeOracle Critical Patch Update, August 2026 Security Update ReviewCVE-2026-65400 · Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
CVE-2024-39943high

Operation CameraSwarm Compromised 14,000+ Dahua Cameras

An exposed operator directory has revealed details of 'Operation CameraSwarm,' a campaign that compromised over 14,000 Dahua cameras, primarily in Ukraine and Russia. The attacker exploited vulnerabilities, including an authentication bypass, and in some cases, leveraged Dahua's cloud relay using only the camera's serial number. The compromised data provided researchers with the attacker's tools, including scanning engines and exploit chains.

zeroday.news ·

An exposed operator directory has revealed details of "Operation CameraSwarm," an attack that compromised over 14,000 Dahua cameras, primarily in Ukraine and Russia, between June 17 and July 22, 2026. The operation was reconstructed by Hunt.io researchers after their AttackCapture system discovered an open HTTP directory on a server at 154.86[.]119.60 on July 23, exposing 407 MB of the attacker's tools across 234 subdirectories.

The leaked files included the operator's scanning engine, exploit chains, an exfiltration bot, and a Windows stealer. Hunt.io's analysis indicates that the attacker utilized multiple methods to gain access. A brute-force engine targeted over 12,300 unique IP addresses. Additionally, an authentication-bypass chain, leveraging two Dahua vulnerabilities from 2021, installed a persistent backdoor account on 1,923 cameras. This backdoor account is designed to survive password changes and, on most firmware, factory resets.

A particularly concerning vector involved reaching 283 cameras solely through their serial numbers via Dahua's cloud relay, bypassing IP addresses entirely. This method exploits a design flaw where Dahua's cloud relay allows any application to connect to a camera behind NAT using only its serial number. Authentication to this relay relies on credentials identical across all Dahua clients. The attacker's logs suggest that 89.4% of live serial numbers exposed an open, unauthenticated channel. While gaining full admin access typically still requires credentials or an authentication bypass, the attacker's logs indicate that most exposed cameras did not require this final step. The device authenticates the session via a token issued by the cloud, which can be obtained using the fixed SDK credentials shared by legitimate Dahua applications.

The attacker's toolkit was not custom-built but rather assembled from various public repositories. Components like the brute-force engine, the bypass chain, the relay tooling, and a recovery-code generator were patched and rewritten, with Russian comments layered over Spanish code in some instances. The toolkit also includes a routine to recover stored device passwords by deriving decryption keys from device class prefixes and serial numbers, without needing a device secret.

One critical tool discovered is an offline recovery-code generator. Given a live serial number, this tool can derive a code offline that unlocks Dahua's cloud-level account-recovery flow, bypassing current credentials. This means that removing a backdoor account would not mitigate this specific vulnerability, which would require Dahua to alter how these codes are derived.

Hunt.io also found a UPX-packed Windows binary, identified as "SalatStealer," staged on the same server, alongside a PowerShell script designed to disable Windows Defender through five different methods, including a Group Policy key that persists across reboots and Defender updates. Researchers consider this a separate, unrelated capability sharing the same infrastructure, not directly part of the camera compromise campaign.

For users of Dahua equipment, or OEM-rebranded lines using the same backend (such as Amcrest, Lorex, Annke, and Swann), recommended actions include checking for and removing any "p2pwn" accounts, disabling P2P on unnecessary devices, confirming firmware is patched against the 2021 bypass vulnerabilities, and rotating all camera credentials, as the exfiltration bot reportedly captured them. However, these steps do not address the recovery-code vulnerability, which rests with the vendor.

It is important to note that the attacker's tools contained incorrect CVE references. The persistent backdoor technique was linked to CVE-2024-39943, which actually refers to a command-injection flaw in Rejetto's HTTP File Server. Similarly, the relay abuse was incorrectly associated with CVE-2025-31702, which Dahua describes as a narrower authenticated privilege-escalation flaw. These inaccuracies could mislead defenders searching for appropriate fixes.

dahuaiotcamerasbotnetvulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

AI is making fraud harder to spot and identity harder to prove

Online fraud has become a routine concern for consumers and businesses that rely on digital accounts, payments and customer service. Experian’s 2026 U.S. Identity & Fraud Report describes a market where scams extend across messages, websites, documents, voices, images and account activity. Security measures that make consumers feel most secure (Source: Experian) Deception spreads across digital ch

security

Researchers find a loophole that lets expired credit cards make unauthorized payments

A team from the University of Massachusetts Amherst has shown that a contactless credit card keeps working past its printed expiration date, even after the cardholder gets a replacement. They named it the Zombie Card attack and presented the findings at USENIX Security 2026. The question behind the loophole “This work is motivated by documented patterns of improper expired card handling. Although

vulnerabilitycritical

8,539 reasons to rethink how vulnerabilities get patched

The window for responding to newly disclosed security flaws is getting shorter. Exploit code can appear quickly, exploitability can be tested soon after disclosure, and organizations have a growing number of weaknesses to sort through. Rapid7’s Q2 2026 Threat Landscape Report counted 8,539 high- and critical-severity vulnerability disclosures, twice the number recorded a year earlier. Source: Rapi

ai

OpenAI confirms ChatGPT is down as logins and signups fail

ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. [...]

ai

Smashing Security podcast #481: Never say this to a robot dog

At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold stat

aicritical

'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

'It is an active threat'