A significant surge in Iranian IP camera targeting was observed as state-aligned actors compromise surveillance networks across multiple nations. This campaign deliberately leverages now-patched IP camera vulnerabilities in widely deployed Hikvision and Dahua hardware to support active military engagements, which Check Point Research (CPR) attributed to Iranian threat actors.
Suspected Iranian attackers gain real-time visual telemetry of strategic geographic locations in Israel, the UAE, Qatar, Bahrain, Kuwait, and Cyprus, as well as specific areas in Lebanon, by exploiting unpatched firmware through command injection and authentication bypass flaws.
CPR security analysts have observed synchronized spikes in camera scanning and exploitation activity that align precisely with geopolitical flashpoints, such as anticipated military strikes and sudden airspace closures. Iranian military likely used these compromised video feeds to support battle damage assessments (BDA) and execute target-correction protocols during missile operations.
“ The attack infrastructure we track combines specific commercial VPN exit nodes (Mullvad, ProtonVPN, Surfshark, NordVPN) and virtual private servers (VPS), and is assessed to be employed by multiple Iran-nexus actors, ” the report added.
The weaponization of civilian and enterprise surveillance systems underscores a dangerous evolution in modern cyber-physical conflict. Organizations must:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
