Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
Overview
Researchers from Hunt.io have reported that over 14,500 Dahua devices were compromised in a campaign known as Operation CameraSwarm, which took place from June 17 to July 22, 2026. The attackers utilized credential attacks, two authentication-bypass vulnerabilities, and a peer-to-peer relay method to gain access. This incident was detailed from a significant amount of leaked data, including a 407 MB directory with over 2,600 files. The implications are serious as these devices could be used for surveillance or other malicious activities, putting users and their privacy at risk. Companies that rely on Dahua products need to take immediate action to secure their devices and protect sensitive information.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Dahua devices, including security cameras and related surveillance equipment.
- Action Required: Users should update their Dahua devices to the latest firmware, change default credentials, and implement stronger authentication measures.
- Timeline: Newly disclosed
Original Article Summary
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. The activity, codenamed Operation CameraSwarm, was reconstructed from a 407 MB exposed working directory containing 2,616 files
Impact
Dahua devices, including security cameras and related surveillance equipment.
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should update their Dahua devices to the latest firmware, change default credentials, and implement stronger authentication measures.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.