Mazda CX5
Як зробити цифрову копію себе. Ось відео —>

Hackers massively attack Hikvision cameras in Ukraine due to critical vulnerability

Cybersecurity researchers from GreyNoise have recorded a surge in hacker attacks on Hikvision surveillance cameras in Ukraine. The attacks were carried out using a known critical vulnerability CVE-2021-36260, which allows remote execution of third-party commands on unprotected devices without authentication.

Leave a comment
Hackers massively attack Hikvision cameras in Ukraine due to critical vulnerability

Cybersecurity researchers from GreyNoise have recorded a surge in hacker attacks on Hikvision surveillance cameras in Ukraine. The attacks were carried out using a known critical vulnerability CVE-2021-36260, which allows remote execution of third-party commands on unprotected devices without authentication.

Chronology and geography of attacks

According to the GreyNoise report, the main wave of activity lasted from September 21 to October 1, 2026, with a peak surge in exploitation attempts observed over a 9-day period starting on September 23. Almost all of the recorded activity was from four IP addresses.

Researchers found that three of the four IP addresses are PureVPN exit nodes located in Lithuania: 195.238.124.178, 195.238.124.181, and 195.238.124.188.

The fourth address belonged to an intra-Ukrainian network, but it is not publicly disclosed. Experts note that since October 7, no new attack attempts have been recorded from these sources.

Although the surge in hacking activity coincided with Russian missile and drone strikes, researchers are currently unable to directly link this cyberactivity to military operations, Cyber ​​Press notes .

Technical details of the vulnerability

The vulnerability, CVE-2021-36260, affects the web server in some Hikvision products. Due to insufficient input validation, hackers can send specially crafted requests that allow them to execute commands in the device’s operating system.

The National Institute of Standards and Technology (NIST) has rated this vulnerability as 9.8 out of 10 on the CVSS 3.1 scale, classifying it as critical. It allows access over the network without an account or user interaction. The attackers used the ready-made Nuclei template from ProjectDiscovery in their attacks.

Intrusion attempts or actual hacking?

GreyNoise emphasizes an important limitation: all captured requests contained only test commands and did not contain malicious code for installation. This indicates an attempt at exploitation, not a confirmed malware infection, permanent access, or successful compromise of operational cameras.

The main risk of hacking video surveillance systems remains the threat of physical surveillance — hackers or enemy intelligence can use cameras to assess the situation on the battlefield before, during, or after kinetic strikes.

Cybersecurity experts are urging all Hikvision devices to update their software. CISA added CVE-2021-36260 to its list of known exploitable vulnerabilities (KEVs) back in January 2022 and strongly recommends installing the latest patch from the manufacturer.

In Chernihiv region, Russian saboteurs will be fought with the help of cameras from a manufacturer on the list of "war sponsors"
In Chernihiv region, Russian saboteurs will be fought with the help of cameras from a manufacturer on the list of "war sponsors"
On the topic
In Chernihiv region, Russian saboteurs will be fought with the help of cameras from a manufacturer on the list of "war sponsors"
Cherkasy police will spend 89 million UAH to install cameras from a Chinese company from the list of "war sponsors"
Cherkasy police will spend 89 million UAH to install cameras from a Chinese company from the list of "war sponsors"
On the topic
Cherkasy police will spend 89 million UAH to install cameras from a Chinese company from the list of "war sponsors"
Read the country's main IT news in our Telegram
Read the country’s main IT news in our Telegram
On the topic
Read the country’s main IT news in our Telegram
Also Read
«Росіяни завжди хочуть когось трахнути». Микита Книш розповів FT, як українські хакери видавали себе за дівчат, зламували камери відеоспостереження та россайти заради перемоги
«Росіяни завжди хочуть когось трахнути». Микита Книш розповів FT, як українські хакери видавали себе за дівчат, зламували камери відеоспостереження та россайти заради перемоги
«Росіяни завжди хочуть когось трахнути». Микита Книш розповів FT, як українські хакери видавали себе за дівчат, зламували камери відеоспостереження та россайти заради перемоги
Видання Financial Times опублікувало статтю про роботу українських хакерів у війні проти рф, засновану на розмові з українським білим хакером Микитою Книшем. Він, як і сотні інших хакерів, допомагає боротися із російськими загарбниками в кіберпросторі. Наводимо адаптований переклад матеріалу. 
Проросійські хакери Killnet оголосили «війну» 10 державам, які підтримують Україну. Що про це пише Wired
Проросійські хакери Killnet оголосили «війну» 10 державам, які підтримують Україну. Що про це пише Wired
Проросійські хакери Killnet оголосили «війну» 10 державам, які підтримують Україну. Що про це пише Wired
Чергова кібератака на держустанови відбулася під виглядом вакансій і вкомплектування військових від шкідника Cobalt Strike Beacon
Чергова кібератака на держустанови відбулася під виглядом вакансій і вкомплектування військових від шкідника Cobalt Strike Beacon
Чергова кібератака на держустанови відбулася під виглядом вакансій і вкомплектування військових від шкідника Cobalt Strike Beacon
Випадково відкрив посилання з вірусом. Що робити? Ось інструкція
Випадково відкрив посилання з вірусом. Що робити? Ось інструкція
Випадково відкрив посилання з вірусом. Що робити? Ось інструкція

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.