
An exposed operator directory has revealed details of 'Operation CameraSwarm,' a campaign that compromised over 14,000 Dahua cameras, primarily in Ukraine and Russia. The attacker exploited vulnerabilities, including an authentication bypass, and in some cases, leveraged Dahua's cloud relay using only the camera's serial number. The compromised data provided researchers with the attacker's tools, including scanning engines and exploit chains.

Cybersecurity researchers have detailed a campaign, dubbed Operation CameraSwarm, that compromised over 14,500 Dahua devices between June and July 2026. The attackers utilized credential stuffing, two authentication bypass vulnerabilities (CVE-2021-33044 and CVE-2021-33045), and a peer-to-peer (P2P) relay technique to gain access. The compromised devices were primarily located in Ukraine and Russia, and users are advised to update firmware and disable P2P services where unnecessary.