Internet‑Wide Scans Target Hikvision Intelligent Security API, Highlighting IoT Camera Exposure Risks
What Happened — Researchers at the SANS Internet Storm Center observed a surge in internet‑wide scans probing the Hikvision Intelligent Security API. The activity, captured on their honeypot network, indicates that threat actors are actively looking for vulnerable or mis‑configured camera endpoints.
Why It Matters for Compliance & Audit Readiness
- Continuous‑monitoring controls required by SOC 2 CC 1.1 must detect and log anomalous network traffic to IoT assets.
- Evidence of due‑diligence around third‑party device hardening can be used as audit artifacts in the Security and Availability criteria.
- Mapping the API exposure to a control gap lets you demonstrate remediation progress in a Trust Center report.
Who Is Affected — Organizations that deploy Hikvision surveillance cameras across sectors such as retail, manufacturing, transportation, and public‑sector facilities.
Recommended Actions —
- Inventory all Hikvision devices and verify firmware versions against the vendor’s security advisories.
- Apply network segmentation and restrict API access to authorized subnets only.
- Enable continuous logging of API calls and integrate logs into a SIEM for SOC 2‑aligned monitoring.
- Document the remediation steps in your control evidence repository for audit readiness. Source: https://isc.sans.edu/diary/rss/33164
Technical Notes — The scans target the “Intelligent Security API” (typically reachable on port 80/443) that can expose camera configuration, video streams, and device status. No specific CVE is cited, but historic Hikvision firmware has contained multiple remote‑code‑execution flaws (e.g., CVE‑2021‑36260). Source: https://isc.sans.edu/diary/rss/33164