安全客July 21, 2026🇨🇳Translated from Chinese

Russian Intelligence Hijacks Exposed Security Cameras in Europe and Ukraine for Military Surveillance

Russian military intelligence services are actively hijacking internet-connected security cameras across Europe and Ukraine to monitor military transport routes, weapons shipments to Kyiv, and Ukrainian troop positions, according to a joint alert issued on July 10 by the Netherlands General Intelligence and Security Service (AIVD) and the Military Intelligence and Security Service (MIVD).

The compromised cameras are not merely passive observers. In Ukraine, the live video feeds have been directly integrated into targeting processes, effectively turning ordinary commercial devices into battlefield aiming tools for strikes against Ukrainian military personnel and equipment. Similar access persists in EU and NATO countries, where the footage is used to gather broader military intelligence unrelated to direct combat operations.

The intrusion technique is disturbingly simple. Attackers use internet-wide scans to identify exposed IP cameras by brand fingerprints, then log directly into devices that still retain factory-default passwords, outdated firmware, or unchanged out-of-the-box configurations. No zero-day vulnerabilities are required. Once inside, image-recognition software automatically scans the video streams for military vehicles and cargo, eliminating the need for continuous human monitoring.

Internet scanning firm Censys mapped the exposure surface and found more than 87,000 cameras running services with known vulnerabilities across the EU, NATO member states, and Ukraine, including over 4,000 devices in Ukraine. In the Netherlands alone, Censys identified 45,386 publicly accessible cameras, of which 1,992 ran vulnerable services. Narrowing the scope to camera-specific software vulnerabilities reduced the Dutch figure to 541 devices.

Two specific vulnerabilities highlighted by Censys are CVE-2016-7407 affecting the Dropbear SSH server and CVE-2021-39275 in Apache HTTP Server version 2.4.49. Both issues were patched years ago and are not listed in CISA’s Known Exploited Vulnerabilities catalog, yet Censys still flagged hundreds of matching hosts.

Although the total number of confirmed compromised cameras remains lower than the overall exposure count, their locations are strategically critical. Many sit along Dutch military transport corridors, prompting authorities to notify affected organizations and request immediate isolation of the devices.

The agencies issued straightforward defensive recommendations: identify all publicly exposed cameras via forgotten port forwards or UPnP mappings, move video streams behind VPNs, replace default passwords and enable multi-factor authentication where possible, adjust camera angles to avoid sensitive logistics areas, and apply security updates promptly while choosing devices with long support lifecycles.

Related articles

securitylab_nState-Sponsored & APT

US Accuses Russian Cybersecurity Specialist D.O. of Void Blizzard Attacks on European Governments and US Companies, Kaspersky Ties Emerge

American authorities have charged Russian information security specialist D.O. with participating in cyberattacks by the Void Blizzard group, also known as Laundry Bear, targeting NATO-aligned European government agencies and at least 11 US companies since 2023. D.O., who previously held a senior position at one of Russia’s largest cybersecurity firms widely identified as Kaspersky, did not plead guilty during a court hearing in Boston. The US Department of Commerce banned the company’s software in 2024 over national security concerns, while European agencies had issued similar warnings earlier. Prosecutors also linked D.O. to a Nizhny Novgorod IT company where he served as deputy director from 2024, although his earlier Kaspersky employment was confirmed through salary records and a former colleague rather than the indictment itself. D.O. graduated from Bauman Moscow State Technical University with a degree in information security, an institution previously flagged by European journalists as a potential training ground for state-linked operatives. Experts note that movement between commercial cybersecurity roles and intelligence structures occurs across countries, but D.O.’s guilt remains to be proven in court.

安全客State-Sponsored & APT

Iranian State-Sponsored Hackers Unveil Cavern C2 Framework: Multi-Format .NET Compilation Bypasses All Security Detection Tools

In July 2026, Check Point Research exposed Cavern Manticore, an Iranian MOIS-linked APT group, actively targeting Israeli IT providers and government entities with a sophisticated modular C2 framework called Cavern (also known as Cav3rn). Unlike previous Iranian groups that rely on public tools, this actor built an entirely custom .NET-based framework deliberately compiled into three incompatible binary formats—pure IL, mixed-mode C++/CLI, and .NET 8 Native AOT—to force analysts to maintain multiple reverse-engineering toolchains and dramatically increase operational costs. The framework achieves near-zero detection rates on VirusTotal by avoiding traditional obfuscation and instead weaponizing compilation formats themselves, with modules running in isolated AppDomains that leave no persistent artifacts. Attackers gain initial access through compromised RMM solutions such as SysAid, abusing legitimate update mechanisms to sideload the Cavern Agent disguised as uxtheme.dll via a WinDirStat DLL side-loading chain. Communication uses XOR encryption with Base64 encoding, fixed Edge User-Agent strings, custom headers, and a unique protocol syntax, while supporting hot updates and aggressive cleanup. The campaign coincides with parallel operations by MuddyWater against regional targets, highlighting Iran’s coordinated escalation in cyberspace and the growing threat of supply-chain trust abuse against MSPs and RMM platforms worldwide.

securitylab_nState-Sponsored & APT

NSA Revives Elite TAO Hacking Unit Behind Stuxnet and WannaCry to Accelerate Cyber Operations Against China and Adversaries

The U.S. National Security Agency has restored the original name Tailored Access Operations (TAO) to its premier cyber intrusion division as part of a major internal restructuring aimed at speeding up offensive operations against hostile nations, including China. The unit, which operated under the name Office of Computer Network Operations (CNO) following the 2016 NSA21 reforms, will once again function as a distinct entity with its own dedicated building at Fort Meade. The change reverses aspects of the earlier reorganization that had merged offensive operations and intelligence collection into larger directorates, a move former employees say hindered collaboration between developers and operators. Deputy NSA Director Tim Kosiba, a former TAO member, oversaw the revival, which was presented to Defense Secretary Pete Hegseth during his visit to the agency’s headquarters. TAO has long been linked to some of the most sophisticated U.S. cyber tools, including those used in the Stuxnet operation against Iran’s nuclear program and the EternalBlue exploit later deployed in the global WannaCry ransomware attack. The unit develops custom malware, persistence mechanisms, and covert access tools for intelligence collection against foreign targets. Former personnel believe the restored structure will improve attack preparation and innovation, particularly in the era of artificial intelligence.