Advertisement
Cyber CrimeDeveloping Story

Russian Intel Targets NATO Logistics

Intelligence agencies report that Russian actors are hijacking IP cameras to monitor military movements across Europe and Ukraine.

··14 hours ago·2 min read
two bullet surveillance cameras attached on wall
Photo by Scott Webb on Unsplash
Advertisement

A campaign by at least one Russian intelligence service is systematically exploiting internet-connected security cameras to track military transport routes, weapons shipments bound for Kyiv, and troop locations. According to a cybersecurity advisory published on July 10 by the Dutch AIVD and MIVD intelligence services, this surveillance operation remains active.

Surveillance Used as Targeting

In Ukraine, the threat has escalated beyond passive observation. The intelligence services note that camera access has been "used in attempts to neutralise Ukrainian military personnel" and destroy equipment. While military intelligence collection continues across other NATO and EU states, those efforts currently focus on logistics rather than direct kinetic strikes.

Scale of the Exposed Surface

Operators are bypassing security by scanning for devices with default passwords, factory settings, or outdated firmware. Research from Censys highlights the scale of the potential risk across the region. While many devices are merely reachable, the firm identified a significant number of hosts running services with known vulnerabilities.

Having a camera publicly accessible doesn't make it hackable.

— Martijn Grooten, a principal security researcher at Censys

  • 87,000+ internet-connected cameras in the EU, NATO, and Ukraine run services matching known-exploited vulnerabilities.
  • 4,000+ of these vulnerable devices are located within Ukraine.
  • 45,386 cameras in the Netherlands are accessible from the public internet.
  • 1,992 of those Dutch cameras show a service with a known-exploited vulnerability.
  • 159 hosts in the Netherlands are affected by dropbearconvert, while 112 are vulnerable to a specific out-of-bounds write.

Operational Realities for Defenders

Despite the high number of reachable devices, the Dutch services clarified in a separate statement that they have only confirmed a small number of actual breaches on military logistics routes. Remediation strategies focus on isolating devices from the public internet by disabling UPnP and port forwarding, replacing default credentials, and utilizing VPNs for access.

Implications for Security Posture

The core danger identified here is the simplicity of the attack vector—often relying on nothing more than default passwords—combined with the high strategic value of the captured footage. For businesses and critical infrastructure operators, this suggests that the primary risk to operational security may not be a sophisticated zero-day, but rather the failure to secure physical assets connected to the public web. Limiting the exposure of internal logistics, ports, and loading docks is essential to preventing adversaries from gaining a persistent, live view of operations.

#iot security#cyber espionage#critical infrastructure#credential security

Sources

Xploitwire Editorial Team

Xploitwire Newsroom

This article's narrative text was drafted by AI (Google Gemini) from the sources listed above, and passed through our automated fact-check gate before publication. It has not been individually reviewed by a human editor prior to going live. Our AI Policy →

← Back to all stories
Advertisement