Cybersecurity researchers at Hunt.io identified a campaign, dubbed "Operation CameraSwarm," that compromised more than 14,530 Dahua devices. The activity occurred between June 17 and July 22, 2026, and was reconstructed from an exposed 407 MB working directory containing tooling, logs, and campaign records. Confirmed compromises were primarily located in Ukraine and Russia.
The attackers utilized three primary methods to gain access to the Dahua devices. Credential attacks accounted for 12,324 unique IP addresses. Authentication bypass flaws, specifically CVE-2021-33044 and CVE-2021-33045, were used to compromise 1,923 cameras, which were also configured with a persistent account. Additionally, 283 cameras were accessed via a peer-to-peer (P2P) relay technique, including devices behind Network Address Translation (NAT).
CVE-2021-33044 and CVE-2021-33045 are authentication-bypass vulnerabilities affecting Dahua cameras and related products. Dahua's advisory rates these flaws at 8.1 on the CVSS scoring system, while the U.S. National Vulnerability Database (NVD) assigns them a CVSS score of 9.8. These vulnerabilities allow attackers to bypass device identity authentication by constructing malicious data packets. Both flaws remain listed in the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog as of August 19, 2026.
Users of affected Dahua products are advised to install the corresponding fix software or newer firmware provided by the vendor. ITRES Labs also recommends disabling P2P functionality when it is not required and regularly checking firmware against the vendor's download site to ensure devices are up to date and secured against known vulnerabilities.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A 35-day campaign, dubbed CameraSwarm, compromised more than 14,500 Dahua IP cameras, primarily in Ukraine and Russia, using a combination of brute-forcing, vulnerability exploits, and cloud-relay attacks. This incident highlights significant security vulnerabilities in widely used surveillance equipment and the potential for widespread unauthorized access to camera feeds and device control.
Cybersecurity researchers at Hunt.io uncovered "Operation CameraSwarm," which compromised over 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws (CVE-2021-33044 and CVE-2021-33045), and a P2P relay technique. This compromise highlights the ongoing risk posed by unpatched vulnerabilities and weak credentials in IoT devices, particularly in critical infrastructure or surveillance contexts.