Russian intelligence: more than 87,000 poorly configured IP cameras are spying on arms deliveries to Ukraine

In this saga : Renseignement russe et surface d'attaque IoT en Europe· Episode 1/3

Cybersecurity 21 h agoAdd to bookmarks

Russian intelligence: more than 87,000 poorly configured IP cameras are spying on arms deliveries to Ukraine
Illustration : Momiji Shirogane

A joint AIVD/MIVD (Dutch intelligence services) assessment dated July 10, 2026 documents a Russian campaign that exploits Internet-exposed IP cameras to track arms convoys to Kyiv through the EU and NATO.

The facts

A joint opinion published on July 10, 2026, by the AIVD (Dutch civil intelligence) and the MIVD (military intelligence) documents a spying campaign attributed to "at least one Russian intelligence service" - without publicly naming the GRU unit concerned. The analysis by the company Censys, taken up by The Hacker News, quantifies the exposure to more than 87,000 Internet-connected cameras whose service version corresponds to a known and exploited CVE, distributed in the EU, NATO member states, and Ukraine (including more than 4,000 vulnerable cameras in Ukraine). In the Netherlands alone, 45,386 exposed cameras are counted, of which 1,992 execute vulnerable services.

Two CVEs are cited as main levers:

  • CVE-2016-7407 - dropbearconvert tool from Dropbear SSH (key import) - 159 Dutch hosts flagged.
  • CVE-2021-39275 - Out-of-bounds write in Apache - 112 Dutch hosts flagged.

The modus operandi described is nothing sophisticated: mass scanning, fingerprinting by brand, exploitation of default passwords, obsolete firmwares, and factory settings. The purpose is military: locating transport routes, weapon shipments to Kyiv, and positions of Ukrainian troops. In Ukraine, the authorities indicate that the captured video streams have been used in attempts to eliminate personnel and destroy equipment.

What this says about the field

No 0-day here. The exploited vulnerabilities are 10 years and 5 years old respectively. This is a useful reminder: the opposing intelligence does not need exotic exploits when a significant portion of the IoT fleet runs in factory configuration, reachable from the first Shodan scan. The lesson is not new but it is cruel: every camera taken out of the box, cabled behind a poorly configured router, and left as is since 2018, becomes a sensor for the adversary.

What to do now

For any organization that operates or distributes IP video surveillance (public, logistics, defense, but also retail and real estate):

  1. Audit Internet exposure: shodan search, censys search on your public IPs (services.software.vendor + services.software.version).
  2. Remove from the Internet what does not need to be there: most of the compromised cameras should not have been exposed. Place behind a VPN or an authenticated reverse proxy.
  3. Change default credentials (again and again) and enforce a rotation policy.
  4. Check firmwares: apply Dropbear patches (>= 2016.75) and Apache for CVE-2021-39275.
  5. Segment the video network from the IT/OT network to limit lateral movement.

Primary sources: the AIVD/MIVD opinion (via ncsc.nl) and the Censys report are the documents to consult - not the press coverage.

Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Was this article helpful?

24 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information