LIVE · cybersecurity feed
Live wire
OpenAI Announced $1B in Defensive Tools for Water UtilitiesAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS CredentialsCVE-2026-59346 · Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host CodeCVE-2026-32475 · Elementor Pro WordPress Plugin Vulnerability Exploited to Hack SitesBroadcom Patches Critical VMware Workstation and Fusion VM-Escape VulnerabilitiesHackers Leak Millions of Airport Passenger Records After Ransom RefusalUsing a VM to Contain an AI AgentCVE-2026-73749 · HPE Patches Critical RCE Vulnerabilities in AOS-CXCVE-2026-14894 · Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE FlawsCisco searched for IOS XR bugs and found so many it rolled them into an update release
cve recordhighexploited in the wild

CVE-2021-33045

Dahua · IP Camera Firmware · Dahua IP Camera Authentication Bypass Vulnerability

· Added to CISA KEV
CVSS
Severityhigh
Weakness
ExploitedYes, in CISA KEV
Ransomware useUnknown
Federal fix dueSep 11, 2024

Description

Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is specified by the client during authentication.

Required action (CISA)

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

References

← Back to the CVE Tracker

Our coverage of CVE-2021-33045

CVE-2021-33044high

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

Cybersecurity researchers have detailed a campaign, dubbed Operation CameraSwarm, that compromised over 14,500 Dahua devices between June and July 2026. The attackers utilized credential stuffing, two authentication bypass vulnerabilities (CVE-2021-33044 and CVE-2021-33045), and a peer-to-peer (P2P) relay technique to gain access. The compromised devices were primarily located in Ukraine and Russia, and users are advised to update firmware and disable P2P services where unnecessary.