Operation CameraSwarm targeted Dahua cameras across multiple countries, focusing on Russian and CIS telecom netblocks. The post Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia appeared first on SecurityWeek.

A recent report indicates that a threat actor, operating under the moniker "Operation CameraSwarm," has compromised approximately 14,000 IP cameras. The campaign reportedly focused on Dahua brand cameras, with the majority of affected devices located within Ukraine and Russia. The targeting appears to have specifically concentrated on telecom network blocks within Russia and the Commonwealth of Independent States (CIS) region.
The reported compromise of Dahua IP cameras suggests the exploitation of vulnerabilities commonly found in internet-connected surveillance devices. These often include default or weak credentials, unpatched firmware vulnerabilities, or misconfigurations that expose management interfaces to the public internet. Given the scale of the reported compromise, it is plausible that the threat actor leveraged automated scanning tools to identify vulnerable devices across broad IP ranges, followed by an exploit chain to gain unauthorized access.
Dahua Technology is a major global manufacturer of video surveillance products and services. Their IP cameras are widely deployed in various sectors, including critical infrastructure, commercial enterprises, and residential settings. The widespread adoption of such devices means that a successful compromise can have significant implications for privacy, security, and potentially even physical safety, depending on the camera's location and purpose.
The likely scope of this operation, impacting 14,000 cameras, represents a substantial number of compromised endpoints. While the report specifically mentions Ukraine and Russia, and CIS telecom netblocks, it is not uncommon for such campaigns to have a broader reach, with the primary focus areas simply representing the most successful or targeted regions. The nature of IP camera compromises often involves the creation of botnets for distributed denial-of-service (DDoS) attacks, or for surveillance purposes.
Typical mitigation guidance for this class of issue includes ensuring that all network-connected devices, especially IP cameras, are running the latest available firmware. Users are strongly advised to change all default credentials to strong, unique passwords immediately upon deployment. Furthermore, restricting access to camera management interfaces to internal networks only, or utilizing virtual private networks (VPNs) for remote access, can significantly reduce exposure to internet-based scanning and exploitation attempts. Network segmentation and intrusion detection systems can also help identify and prevent unauthorized access.
This incident underscores the persistent challenge of securing internet-of-things (IoT) devices, particularly those deployed in large numbers and often left unmanaged after initial installation. The geopolitical context of the reported targeting in Ukraine and Russia further highlights how widely deployed technologies can become instruments in broader conflicts or cyber espionage campaigns, emphasizing the critical need for robust security practices across all connected infrastructure.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed