Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
Summary
Cybersecurity researchers have identified a campaign, dubbed Operation CameraSwarm, that compromised over 14,500 Dahua devices using credential attacks, authentication bypass flaws, and a P2P relay technique. This activity occurred between June 17 and July 22, 2026, and was uncovered from a large set of exposed files.
IFF Assessment
The article details a significant compromise of IoT devices, indicating a successful exploitation of vulnerabilities by threat actors.
Defender Context
This incident highlights the ongoing risks associated with unsecured IoT devices, particularly those from vendors like Dahua. Defenders should prioritize patching known vulnerabilities, enforcing strong authentication, and monitoring for unusual traffic patterns on networked devices to prevent similar compromises.