Bleepingcomputer CameraSwarm Operation Compromises Over 14,500 Dahua IP Cameras
Article Content
- •Over 14,500 Dahua IP cameras were compromised in a 35-day operation.
- •Attack methods included brute-forcing logins and exploiting offline recovery codes.
- •Hunt.io recovered extensive data from the attacker's exposed server, aiding in the investigation.
Between June 17 and July 22, 2026, hackers compromised over 14,500 Dahua IP cameras, primarily in Ukraine and Russia, in a campaign dubbed CameraSwarm. The attackers exploited vulnerabilities, brute-forced logins, and utilized offline recovery codes from camera serial numbers. Hunt.io discovered the operation after finding an exposed directory containing 2,616 files, including source code and credentials. The attack toolkit allowed access to cameras without needing passwords for most devices. The campaign was reported to national CERTs and Dahua's PSIRT on August 10, 2026. Users are advised to check for a 'p2pwn' account and apply firmware updates to mitigate risks. The vulnerabilities referenced include CVE-2021-33044 and CVE-2021-33045, both of which have known patches.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (15)
Following this threat?
Track CVE-2021-33044 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Human Attacker Exploits Marimo RCE at Machine Speed A human attacker exploited CVE-2026-39987, a pre-authentication remote code execution vulnerability in Marimo notebooks, achieving a rapid transition from an open WebSocket to SSH access in just eight seconds. The attacker utilized a hand-rolled Python toolkit, bypassing detection mechanisms designed for AI-driven…
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…