At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine to spy on military logistics, according to a July 10 advisory from the Netherlands’ AIVD and MIVD intelligence services. The operation uses exposed cameras with default passwords, obsolete firmware, and factory settings to monitor military transport routes, weapons shipments to Kyiv, and Ukrainian troop positions. In Ukraine, camera access has been used to target military personnel and equipment. Across EU and NATO states, the surveillance collects military intelligence unrelated to the war.
Internet scanning firm Censys identified over 87,000 internet-connected cameras across the EU, NATO members, and Ukraine running services with known-exploited vulnerabilities, with more than 4,000 in Ukraine alone. In the Netherlands, 45,386 cameras were reachable, with 1,992 flagged for vulnerable services. Two specific CVEs were highlighted: CVE-2016-7407 (Dropbear SSH server) and CVE-2021-39275 (Apache HTTP Server), though neither is in CISA’s Known Exploited Vulnerabilities catalog. The Dutch services confirmed only a small number of cameras were breached on military logistics routes in the Netherlands, with affected organizations notified.
Defenders are advised to identify exposed cameras, remove them from the public internet via VPNs, replace default credentials, enable MFA, patch firmware, and carefully aim lenses away from sensitive areas. The threat is amplified by the simplicity of entry—often a default login—and the strategic value of camera feeds for real-time physical surveillance.
CVEs: CVE-2016-7407, CVE-2021-39275
Attack groups: Russian Intelligence Services
Products: Dropbear SSH, Apache HTTP Server
Original source: thehackernews.com