LIVE · cybersecurity feed
Live wire
vulnerability

Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)

We have been following issues with Hikvision cameras for a long, long time. Like many similar products, Hikvision cameras have a long history of vulnerabilities and are often targeted by internet-wide scans that our honeypot network detects.

zeroday.news · 13d ago

Reports indicate a recent surge in internet-wide scanning activity targeting the Hikvision Intelligent Security API. This observed scanning behavior, detected by honeypot networks, suggests attackers are actively probing for vulnerable Hikvision devices exposed to the internet. The activity was specifically noted on Sunday, July 19th.

The Hikvision Intelligent Security API is a component found in various Hikvision camera models, enabling remote management and integration with other security systems. While the specific vulnerability or configuration being targeted by these scans was not detailed, such API endpoints are frequently exploited for unauthorized access, data exfiltration, or to incorporate devices into botnets. Attackers often leverage automated tools to identify devices responding to specific API calls or exhibiting known vulnerable behaviors.

Hikvision, a prominent manufacturer in the video surveillance industry, produces a wide range of IP cameras and network video recorders. Products in this category commonly expose administrative interfaces and APIs to facilitate remote access and system management. The widespread deployment of these devices, often with default configurations or insufficient security hardening, makes them attractive targets for opportunistic attackers conducting internet-wide scans.

The scope of potential compromise from such scanning activity can be significant, given the large install base of Hikvision products globally. While a scan merely indicates probing, successful exploitation could lead to unauthorized viewing of live camera feeds, manipulation of recorded footage, denial-of-service attacks against the devices, or the use of compromised cameras as entry points into broader corporate or home networks.

Mitigation for this class of issue typically involves several key steps. Users of Hikvision devices should ensure their firmware is updated to the latest available version, as updates frequently patch known security vulnerabilities. It is also crucial to change all default passwords to strong, unique credentials. Network segmentation can limit the exposure of these devices, placing them on isolated networks separate from critical infrastructure. Furthermore, disabling unnecessary services and restricting access to administrative interfaces to trusted IP addresses or internal networks can significantly reduce the attack surface.

This reported scanning activity underscores a persistent challenge in the realm of IoT and connected devices. The long history of vulnerabilities associated with many internet-connected cameras and similar products highlights the ongoing need for robust security practices from both manufacturers and end-users. The continuous monitoring by honeypot networks provides valuable intelligence into these evolving threat landscapes, enabling a better understanding of attacker methodologies and targeted systems.

vulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]

breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.