Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

July 25, 2026

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

July 25, 2026

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

July 25, 2026
Facebook X (Twitter) Instagram
Sunday, July 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
News

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

Team-CWDBy Team-CWDJuly 25, 2026No Comments5 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops.

That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands’ civilian and military intelligence services, which describe the operation as ongoing.

In Ukraine, the surveillance has not stayed passive. Camera access there has been “used in attempts to neutralise Ukrainian military personnel” and destroy their equipment, the services say, turning an exposed roadside or business camera into a targeting aid.

Across EU and NATO states, the services add, the same camera access is also collecting military intelligence that has nothing to do with the war.

Getting in is rarely the hard part. The operators scan the internet for exposed devices, fingerprint IP cameras by brand, and walk into the ones still running default passwords, obsolete firmware, and factory settings nobody changed.

From there, image-recognition software does the watching, running automated searches through the video for military vehicles and the cargo they carry. None of the access the advisory describes needs a zero-day.

Just how exposed are these cameras?

Being reachable from the internet is not the same as being hacked. “Having a camera publicly accessible doesn’t make it hackable,” writes Martijn Grooten, a principal security researcher at Censys, the internet-scanning firm, in the company’s own analysis of the exposed surface.

The surface, though, is enormous. Across the EU, NATO members, and Ukraine, Censys counted more than 87,000 internet-connected cameras running a service whose version matches a known-exploited vulnerability, a total it calls a lower bound. More than 4,000 of them sit in Ukraine.

That total counts hosts running any vulnerable service, not cameras whose own software is broken, a caveat Censys raises itself. In the Netherlands, Censys found 45,386 cameras reachable from the public internet and flagged 1,992 as running a service with a known-exploited vulnerability.

Narrow that to bugs in the camera software itself, and the figure drops to 541. Censys keeps the wider count on the logic that a foothold on one service can often be used to take over the whole host.

Those version matches deserve their own caveat: a service banner is not a reachable exploit. Of the two bugs Censys highlights, CVE-2016-7407 sits in dropbearconvert, a local key-import tool in the Dropbear SSH server that runs code only when someone converts a malicious key file. It was fixed in July 2016, and Censys flagged 159 Dutch hosts for it.

CVE-2021-39275 is an out-of-bounds write that Apache itself rates low, since no bundled module feeds untrusted data to the affected function, though a third-party one might. It was patched in Apache 2.4.49 in 2021, and 112 Dutch hosts run a matching version. Censys counts both as exploited in the wild, though neither sits in CISA’s Known Exploited Vulnerabilities catalog.

Set that exposed surface against confirmed intrusions. In a separate statement, the Dutch services said they had actually caught only a small number of cameras breached, sitting directly on military logistics routes inside the Netherlands, and that the organisations running them have since been warned so they could lock things down.

The Hacker News has asked Censys whether its counts are version matches alone or confirm a vulnerable configuration, and what evidence classifies the two CVEs as exploited in the wild; we will update this story with any response.

What defenders should do

The recommended fixes are the dull, effective ones:

  • Start by finding what is exposed: which cameras are reachable from the public internet through a forgotten port-forward, a UPnP mapping, or a vendor cloud relay. Prioritise the ones overlooking transport routes, ports, and other sensitive sites, and check their logs for access you do not recognise.
  • Keep the video stream off the public internet: turn off port forwarding and UPnP, and reach cameras through a VPN.
  • Replace default credentials and turn on MFA where the device supports it; where it does not, keep that camera off the public internet entirely.
  • Aim the lens deliberately: keep logistics routes, loading docks, and other sensitive spots out of frame, and mask what you cannot avoid.
  • Patch firmware and software, and when it is time to buy, choose cameras that ship with years of security support, not months.

The services say they have not observed camera-derived intelligence being used for military attacks outside Ukraine. What makes the threat portable is how ordinary both halves are: the entry is often just a default login, and the value is set by where the camera happens to point.

A compromised camera hands an adversary a live read on physical operations, when the trucks move, and who comes and goes, no deeper breach of the network required. The fix, then, is not just patching the device; it is taking it off the public internet and controlling what it can see.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMythos Didn’t Break Your Security Program. Your Exposure Window Could.
Next Article HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
Team-CWD
  • Website

Related Posts

News

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

July 25, 2026
News

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

July 25, 2026
News

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

July 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Mobile app permissions (still) matter more than you may think

February 27, 2026

Can password managers get hacked? Here’s what to know

November 14, 2025

Look out for phony verification pages spreading malware

September 14, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.