Cybersecurity 13 h agoAdd to bookmarks

A joint AIVD/MIVD (Dutch intelligence services) assessment dated July 10, 2026 documents a Russian campaign that exploits Internet-exposed IP cameras to track arms convoys to Kyiv through the EU and NATO.
A joint opinion published on July 10, 2026, by the AIVD (Dutch civil intelligence) and the MIVD (military intelligence) documents a spying campaign attributed to "at least one Russian intelligence service" - without publicly naming the GRU unit concerned. The analysis by the company Censys, taken up by The Hacker News, quantifies the exposure to more than 87,000 Internet-connected cameras whose service version corresponds to a known and exploited CVE, distributed in the EU, NATO member states, and Ukraine (including more than 4,000 vulnerable cameras in Ukraine). In the Netherlands alone, 45,386 exposed cameras are counted, of which 1,992 execute vulnerable services.
Two CVEs are cited as main levers:
dropbearconvert tool from Dropbear SSH (key import) - 159 Dutch hosts flagged.The modus operandi described is nothing sophisticated: mass scanning, fingerprinting by brand, exploitation of default passwords, obsolete firmwares, and factory settings. The purpose is military: locating transport routes, weapon shipments to Kyiv, and positions of Ukrainian troops. In Ukraine, the authorities indicate that the captured video streams have been used in attempts to eliminate personnel and destroy equipment.
No 0-day here. The exploited vulnerabilities are 10 years and 5 years old respectively. This is a useful reminder: the opposing intelligence does not need exotic exploits when a significant portion of the IoT fleet runs in factory configuration, reachable from the first Shodan scan. The lesson is not new but it is cruel: every camera taken out of the box, cabled behind a poorly configured router, and left as is since 2018, becomes a sensor for the adversary.
For any organization that operates or distributes IP video surveillance (public, logistics, defense, but also retail and real estate):
shodan search, censys search on your public IPs (services.software.vendor + services.software.version).Primary sources: the AIVD/MIVD opinion (via ncsc.nl) and the Censys report are the documents to consult - not the press coverage.
Article produced by artificial intelligence, reviewed under human editorial control.
Renseignement russe et surface d'attaque IoT en Europe