Russian Intel Targets NATO Logistics
Intelligence agencies report that Russian actors are hijacking IP cameras to monitor military movements across Europe and Ukraine.
A campaign by at least one Russian intelligence service is systematically exploiting internet-connected security cameras to track military transport routes, weapons shipments bound for Kyiv, and troop locations. According to a cybersecurity advisory published on July 10 by the Dutch AIVD and MIVD intelligence services, this surveillance operation remains active.
Surveillance Used as Targeting
In Ukraine, the threat has escalated beyond passive observation. The intelligence services note that camera access has been "used in attempts to neutralise Ukrainian military personnel" and destroy equipment. While military intelligence collection continues across other NATO and EU states, those efforts currently focus on logistics rather than direct kinetic strikes.
Scale of the Exposed Surface
Operators are bypassing security by scanning for devices with default passwords, factory settings, or outdated firmware. Research from Censys highlights the scale of the potential risk across the region. While many devices are merely reachable, the firm identified a significant number of hosts running services with known vulnerabilities.
Having a camera publicly accessible doesn't make it hackable.
— Martijn Grooten, a principal security researcher at Censys
- 87,000+ internet-connected cameras in the EU, NATO, and Ukraine run services matching known-exploited vulnerabilities.
- 4,000+ of these vulnerable devices are located within Ukraine.
- 45,386 cameras in the Netherlands are accessible from the public internet.
- 1,992 of those Dutch cameras show a service with a known-exploited vulnerability.
- 159 hosts in the Netherlands are affected by dropbearconvert, while 112 are vulnerable to a specific out-of-bounds write.
Operational Realities for Defenders
Despite the high number of reachable devices, the Dutch services clarified in a separate statement that they have only confirmed a small number of actual breaches on military logistics routes. Remediation strategies focus on isolating devices from the public internet by disabling UPnP and port forwarding, replacing default credentials, and utilizing VPNs for access.
Implications for Security Posture
The core danger identified here is the simplicity of the attack vector—often relying on nothing more than default passwords—combined with the high strategic value of the captured footage. For businesses and critical infrastructure operators, this suggests that the primary risk to operational security may not be a sophisticated zero-day, but rather the failure to secure physical assets connected to the public web. Limiting the exposure of internal logistics, ports, and loading docks is essential to preventing adversaries from gaining a persistent, live view of operations.
Sources
- The Hacker News Original source
- weapons shipments bound for Kyiv Also reporting
- cybersecurity advisory Also reporting
- "used in attempts to neutralise Ukrainian military personnel" Also reporting
- Censys Also reporting
- dropbearconvert Also reporting
- out-of-bounds write Also reporting
- separate statement Also reporting
Continue Reading
Unicode Trick Fuels Million-Email Phishing Surge
A campaign hides 'funding' lure words with invisible Unicode tags, splitting keywords to slip past filters.
French hospital fined €500,000 after breach exposes data of 727,000
CNIL fines Hôpital privé de la Loire for security failures that led to a breach exposing data of over 727,000 people.
AI-Driven Malware Marks Exilwire's Underground Trade in Breached Hosts
BraZetsu framework turns compromised Windows machines into commercial inventory for Intermediary access brokers.