Operation Camera Swarm And The New IoT Reality

August 19
3 mins

Episode Description

Here is your briefing for Wednesday, August 19, 2026. [pause 1.0] Five stories that show how quickly yesterday's assumptions become today's attack surface. [pause 0.8] Security researchers at Hunt.io reconstructed a campaign that compromised more than 14,530 Dahua devices between mid-June and late July using credential stuffing, two authentication bypass flaws, and a peer-to-peer relay technique. The activity, dubbed Operation CameraSwarm, came from an exposed 407 MB working directory containing tooling, logs, and campaign records. Compromises concentrated in Ukraine and Russia, with 1,923 cameras left with a persistent account and 283 reached via the P2P path. Users are advised to apply vendor firmware or disable P2P where possible. That's the headline from The Hacker News, and it demonstrates that commodity IoT hardware remains an attractive, lightly defended target even when the tooling leaks in public. [pause 1.2] The Cybersecurity and Infrastructure Security Agency on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog. The additions include CVE-2026-65400, an improper authentication issue in Apple macOS Screen Sharing that allows network attackers to authenticate without credentials

Support the show

See all episodes