Наталя ХандусенкоHot News
9 October 2026, 12:55
2026-10-09
Hackers massively attack Hikvision cameras in Ukraine due to critical vulnerability
Cybersecurity researchers from GreyNoise have recorded a surge in hacker attacks on Hikvision surveillance cameras in Ukraine. The attacks were carried out using a known critical vulnerability CVE-2021-36260, which allows remote execution of third-party commands on unprotected devices without authentication.
Cybersecurity researchers from GreyNoise have recorded a surge in hacker attacks on Hikvision surveillance cameras in Ukraine. The attacks were carried out using a known critical vulnerability CVE-2021-36260, which allows remote execution of third-party commands on unprotected devices without authentication.
Chronology and geography of attacks
According to the GreyNoise report, the main wave of activity lasted from September 21 to October 1, 2026, with a peak surge in exploitation attempts observed over a 9-day period starting on September 23. Almost all of the recorded activity was from four IP addresses.
Researchers found that three of the four IP addresses are PureVPN exit nodes located in Lithuania: 195.238.124.178, 195.238.124.181, and 195.238.124.188.
The fourth address belonged to an intra-Ukrainian network, but it is not publicly disclosed. Experts note that since October 7, no new attack attempts have been recorded from these sources.
Although the surge in hacking activity coincided with Russian missile and drone strikes, researchers are currently unable to directly link this cyberactivity to military operations, Cyber Press notes .
Technical details of the vulnerability
The vulnerability, CVE-2021-36260, affects the web server in some Hikvision products. Due to insufficient input validation, hackers can send specially crafted requests that allow them to execute commands in the device’s operating system.
The National Institute of Standards and Technology (NIST) has rated this vulnerability as 9.8 out of 10 on the CVSS 3.1 scale, classifying it as critical. It allows access over the network without an account or user interaction. The attackers used the ready-made Nuclei template from ProjectDiscovery in their attacks.
Intrusion attempts or actual hacking?
GreyNoise emphasizes an important limitation: all captured requests contained only test commands and did not contain malicious code for installation. This indicates an attempt at exploitation, not a confirmed malware infection, permanent access, or successful compromise of operational cameras.
The main risk of hacking video surveillance systems remains the threat of physical surveillance — hackers or enemy intelligence can use cameras to assess the situation on the battlefield before, during, or after kinetic strikes.
Cybersecurity experts are urging all Hikvision devices to update their software. CISA added CVE-2021-36260 to its list of known exploitable vulnerabilities (KEVs) back in January 2022 and strongly recommends installing the latest patch from the manufacturer.
«Росіяни завжди хочуть когось трахнути». Микита Книш розповів FT, як українські хакери видавали себе за дівчат, зламували камери відеоспостереження та россайти заради перемоги
Видання Financial Times опублікувало статтю про роботу українських хакерів у війні проти рф, засновану на розмові з українським білим хакером Микитою Книшем. Він, як і сотні інших хакерів, допомагає боротися із російськими загарбниками в кіберпросторі. Наводимо адаптований переклад матеріалу.