CVE-2021-39275
CVSS 9.8 CRITICAL: ap_escape_quotes() may write beyond the end of a buffer when given malicious input. EPSS 39% (98th percentile).
Threats & Adversaries · APT / Espionage
An exposed camera is not just a privacy problem. In this campaign, a Russian intelligence service is treating internet-reachable CCTV as persistent surveillance infrastructure, using the feed itself to watch military logistics and, in Ukraine, to help target personnel and equipment.
The AIVD and MIVD say the activity is ongoing across Europe and Ukraine. Censys says the exposed surface is much larger than one case, with more than 87,000 internet-connected devices matching known-exploited services, including thousands in Ukraine and tens of thousands in the Netherlands alone.
The weak point is mundane: unchanged passwords, default settings, and devices left reachable from the internet. That means a single camera can expose route patterns and cargo movement without any deeper breach of the network.
2 sources · Jul 20
CVSS 9.8 CRITICAL: ap_escape_quotes() may write beyond the end of a buffer when given malicious input. EPSS 39% (98th percentile).
CVSS 9.8 CRITICAL: the dropbearconvert command in Dropbear SSH before 2016.74 allows attackers to execute arbitrary code via a crafted… EPSS 6% (93rd percentile).
The Hacker News
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
Russian intelligence hijacks exposed cameras to track military routes as Censys flags 87,000 devices matching known-exploited services in Europe.
originalThe Record from Recorded Future
NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says
Dutch intelligence officials report that at least one Russian agency is compromising internet-connected cameras across Europe to spy on military logistics and Ukrainian personnel.
originalPart of the PlainSec briefing for 2026-07-20
Every edition of this story: Exposed Cameras Become State ISR Tools