TechRadar News.
Technology

Hikvision Camera Exploit Attempts Rise Sharply Across Ukraine

Hikvision Camera Exploit Attempts Rise Sharply Across Ukraine

GreyNoise, a service that tracks worldwide internet noise, noted a clear increase in scanning and remote‑code‑execution (RCE) attempts directed at video‑surveillance gear in Ukraine between September 21 and October 1, 2026. The activity centered on the known critical flaw CVE‑2021‑36260, which permits unauthenticated command injection on certain Hikvision devices that have not been updated with the latest firmware.

First disclosed in 2021, the vulnerability remains unpatched on a large fleet of cameras still deployed in public institutions, transport hubs and private sites. GreyNoise recorded automated probes that first identify Hikvision hardware and then try to exploit the command‑injection bug to run arbitrary code. While the evidence does not prove successful compromises, the sheer number of attempts indicates a growing interest from threat actors seeking espionage or disruptive outcomes.

The ongoing conflict in Ukraine has heightened the strategic importance of surveillance infrastructure, making cameras attractive to both state‑aligned and opportunistic groups after visual intelligence or a foothold in critical networks. Analysts warn that compromised cameras can act as entry points for broader network infiltration, enabling lateral movement, data exfiltration or service disruption. The timing aligns with a wider wave of cyber operations targeting Ukrainian assets, hinting at a coordinated push to exploit lingering security gaps.

Hikvision, one of the world’s biggest security‑equipment manufacturers, has released patches for CVE‑2021‑36260, yet adoption has been uneven. Many organisations postpone updates because of operational constraints, legacy hardware or limited awareness of the risk. Cybersecurity experts stress immediate remediation: apply the vendor’s firmware, isolate cameras on separate network segments and enforce strict access controls. Some Ukrainian authorities have already issued advisories urging public and private entities to audit their surveillance deployments and confirm that all devices run the latest security revisions.

Looking ahead, the spike in exploitation attempts may trigger further defensive actions. GreyNoise plans to keep monitoring the activity, while security firms anticipate that threat groups will adjust tactics if the vulnerability is broadly mitigated. The episode highlights the broader challenge of protecting Internet‑of‑Things devices that were not originally built with robust patch‑management processes. As the situation evolves, both manufacturers and end‑users will need to prioritize timely updates and network segmentation to shrink the attack surface of critical visual‑monitoring systems.

TechRadar Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related