LIVE · cybersecurity feed
Live wire
CVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on HostCISA orders feds to patch actively exploited TrueConf Server flawsCVE-2026-69836 · Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
security

Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia

Operation CameraSwarm targeted Dahua cameras across multiple countries, focusing on Russian and CIS telecom netblocks. The post Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia appeared first on SecurityWeek.

zeroday.news ·

A recent report indicates that a threat actor, operating under the moniker "Operation CameraSwarm," has compromised approximately 14,000 IP cameras. The campaign reportedly focused on Dahua brand cameras, with the majority of affected devices located within Ukraine and Russia. The targeting appears to have specifically concentrated on telecom network blocks within Russia and the Commonwealth of Independent States (CIS) region.

The reported compromise of Dahua IP cameras suggests the exploitation of vulnerabilities commonly found in internet-connected surveillance devices. These often include default or weak credentials, unpatched firmware vulnerabilities, or misconfigurations that expose management interfaces to the public internet. Given the scale of the reported compromise, it is plausible that the threat actor leveraged automated scanning tools to identify vulnerable devices across broad IP ranges, followed by an exploit chain to gain unauthorized access.

Dahua Technology is a major global manufacturer of video surveillance products and services. Their IP cameras are widely deployed in various sectors, including critical infrastructure, commercial enterprises, and residential settings. The widespread adoption of such devices means that a successful compromise can have significant implications for privacy, security, and potentially even physical safety, depending on the camera's location and purpose.

The likely scope of this operation, impacting 14,000 cameras, represents a substantial number of compromised endpoints. While the report specifically mentions Ukraine and Russia, and CIS telecom netblocks, it is not uncommon for such campaigns to have a broader reach, with the primary focus areas simply representing the most successful or targeted regions. The nature of IP camera compromises often involves the creation of botnets for distributed denial-of-service (DDoS) attacks, or for surveillance purposes.

Typical mitigation guidance for this class of issue includes ensuring that all network-connected devices, especially IP cameras, are running the latest available firmware. Users are strongly advised to change all default credentials to strong, unique passwords immediately upon deployment. Furthermore, restricting access to camera management interfaces to internal networks only, or utilizing virtual private networks (VPNs) for remote access, can significantly reduce exposure to internet-based scanning and exploitation attempts. Network segmentation and intrusion detection systems can also help identify and prevent unauthorized access.

This incident underscores the persistent challenge of securing internet-of-things (IoT) devices, particularly those deployed in large numbers and often left unmanaged after initial installation. The geopolitical context of the reported targeting in Ukraine and Russia further highlights how widely deployed technologies can become instruments in broader conflicts or cyber espionage campaigns, emphasizing the critical need for robust security practices across all connected infrastructure.

ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware. The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight appeared first on SecurityWeek.

breach

AWS Security makes an inscrutable choice

Quarantining leaked credentials is not good enough

ai

Say it once: introducing Bot Preference Sync

Cloudflare's new Bot Preference Sync automatically aligns your robots.txt file with your AI bot policies for Search, Agent, and Training. Easily manage which bots access your content without maintaining static files.

cloud security

Cloudflare Launches Bot Preference Sync for AI Traffic Management

Cloudflare has introduced Bot Preference Sync, a new feature designed to simplify the management of AI bot traffic. This tool automatically updates a website's robots.txt file to align with the user's AI bot configuration settings. The goal is to prevent discrepancies between stated preferences and enforced rules, ensuring better control over how AI crawlers access and use website content.

CVE-2024-3094high

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

Attackers are increasingly targeting the software development lifecycle (SDLC) supply chain by compromising developer tools, CI/CD pipelines, and open-source packages. Recent attacks like the ChainDrop npm worm demonstrate sophisticated methods to steal credentials, backdoor developer environments, and propagate malware. Securing the SDLC requires a shift from reactive code scanning to strict execution control and continuous visibility across developer endpoints, build pipelines, and cloud runtimes.

patch

Friday Squid Blogging: Neon Flying Squid

The neon flying squid can fly in formation. The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion. They were probably neon flying squid (Ommastrephes bartramii),