We have been following issues with Hikvision cameras for a long, long time. Like many similar products, Hikvision cameras have a long history of vulnerabilities and are often targeted by internet-wide scans that our honeypot network detects.

Reports indicate a recent surge in internet-wide scanning activity targeting the Hikvision Intelligent Security API. This observed scanning behavior, detected by honeypot networks, suggests attackers are actively probing for vulnerable Hikvision devices exposed to the internet. The activity was specifically noted on Sunday, July 19th.
The Hikvision Intelligent Security API is a component found in various Hikvision camera models, enabling remote management and integration with other security systems. While the specific vulnerability or configuration being targeted by these scans was not detailed, such API endpoints are frequently exploited for unauthorized access, data exfiltration, or to incorporate devices into botnets. Attackers often leverage automated tools to identify devices responding to specific API calls or exhibiting known vulnerable behaviors.
Hikvision, a prominent manufacturer in the video surveillance industry, produces a wide range of IP cameras and network video recorders. Products in this category commonly expose administrative interfaces and APIs to facilitate remote access and system management. The widespread deployment of these devices, often with default configurations or insufficient security hardening, makes them attractive targets for opportunistic attackers conducting internet-wide scans.
The scope of potential compromise from such scanning activity can be significant, given the large install base of Hikvision products globally. While a scan merely indicates probing, successful exploitation could lead to unauthorized viewing of live camera feeds, manipulation of recorded footage, denial-of-service attacks against the devices, or the use of compromised cameras as entry points into broader corporate or home networks.
Mitigation for this class of issue typically involves several key steps. Users of Hikvision devices should ensure their firmware is updated to the latest available version, as updates frequently patch known security vulnerabilities. It is also crucial to change all default passwords to strong, unique credentials. Network segmentation can limit the exposure of these devices, placing them on isolated networks separate from critical infrastructure. Furthermore, disabling unnecessary services and restricting access to administrative interfaces to trusted IP addresses or internal networks can significantly reduce the attack surface.
This reported scanning activity underscores a persistent challenge in the realm of IoT and connected devices. The long history of vulnerabilities associated with many internet-connected cameras and similar products highlights the ongoing need for robust security practices from both manufacturers and end-users. The continuous monitoring by honeypot networks provides valuable intelligence into these evolving threat landscapes, enabling a better understanding of attacker methodologies and targeted systems.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.