HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Actor Hijacks 14,000+ Dahua Surveillance Cameras via Exposed Cloud Relay and Authentication Bypass

A threat actor leveraged an open operator directory and Dahua's insecure cloud‑relay to take control of over 14,000 cameras in Ukraine and Russia. The breach highlights a misconfiguration that SOC 2 programs must monitor and evidence for audit readiness.

LiveThreat™ Intelligence · 📅 August 20, 2026· 📰 securityaffairs.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
4 recommended
📰
Source
securityaffairs.com

Actor Hijacks 14,000+ Dahua Surveillance Cameras via Exposed Cloud Relay and Authentication Bypass

What Happened — Researchers at Hunt.io uncovered an open HTTP directory that exposed the tooling of a threat actor who compromised more than 14,000 Dahua IP cameras across Ukraine and Russia between 17 June and 22 July 2026. The attacker leveraged two 2021 Dahua vulnerabilities to plant persistent back‑door accounts and, more critically, abused Dahua’s cloud‑relay service, which authenticates devices with a static SDK credential shared by every client. Because the relay requires only a serial number, 89 % of live cameras were reachable without any password.

Why It Matters for Compliance & Audit Readiness

  • The incident is a textbook example of a misconfiguration‑driven control gap that SOC 2 continuous‑compliance programs are built to detect, monitor, and evidence.
  • Mapping the affected control (e.g., CC6.1 System Operations – Logical Access) to audit evidence becomes essential when a vendor’s default cloud‑relay authentication is insecure.
  • Continuous evidence collection (e.g., automated scans of exposed directories, configuration drift alerts) provides the defensible audit trail required for the Security and Availability Trust Services Criteria.

Who Is Affected — Video‑surveillance manufacturers, critical‑infrastructure operators, retail and logistics sites that deploy Dahua cameras, and any organization that relies on the cloud‑relay service for remote access.

Recommended Actions

  • Inventory all Dahua (or similar) cameras and verify whether they use the vulnerable cloud‑relay authentication.
  • Apply vendor patches for the 2021 CVEs and disable the default SDK credentials where possible.
  • Implement continuous configuration monitoring to detect open directories, default credentials, and unauthorized back‑door accounts.
  • Map the incident to SOC 2 controls (e.g., CC6.1, CC7.2) and capture evidence of remediation for audit readiness.

Technical Notes — The actor used a brute‑force engine against IP addresses, an authentication‑bypass chain exploiting two 2021 Dahua CVEs, and a serial‑number‑only cloud‑relay path that required no password. The back‑door account persisted through firmware resets. Source: Security Affairs

📰 Original Source
https://securityaffairs.com/197527/iot/inside-operation-cameraswarm-how-one-actor-took-over-14000-dahua-cameras.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →