Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Dahua Cameras Breached: Persistent Backdoor Vulnerabilities

Dahua Cameras Breached: Persistent Backdoor Vulnerabilities

Posted on September 4, 2026 By CWS

A significant security breach has affected more than 14,000 Dahua internet-connected cameras, showcasing the vulnerability of surveillance equipment as a conduit for unauthorized access to video feeds and device settings. This large-scale operation spanned 35 days, targeting devices globally, with notable breaches in Ukraine and Russia. The incident highlights the potential for unattended devices to offer enduring, clandestine access to intruders.

Global Impact of Dahua Camera Breach

The breach involved scanning for exposed camera management services, exploiting weak credentials, and leveraging two known authentication-bypass vulnerabilities in unpatched devices. A cloud relay method was employed, allowing access to cameras obscured by network address translation by using serial numbers, making even non-public devices susceptible to attack.

Hunt.io analysts uncovered this activity after discovering an openly accessible directory containing 2,616 files and campaign tools. According to a Hunt.io report shared with Cyber Security News, the findings revealed multiple attack vectors, persistent access tools, and an unrelated Windows payload.

Persistent Backdoor Access

One of the most alarming discoveries was the persistence of access. After obtaining administrator rights through the vulnerabilities CVE-2021-33044 and CVE-2021-33045, attackers created an additional account via the camera’s remote management interface. This account is independent of the main administrator password, meaning a password change does not eliminate it. In most affected firmware, even a factory reset fails to remove this hidden access. Hunt.io identified 1,923 cameras with this unauthorized account.

This revelation transforms a routine password update into a full-fledged compromise investigation, particularly for organizations utilizing cameras in sensitive areas. Despite available patches, exposed and unpatched cameras remain attractive targets, emphasizing the importance of understanding the risks of direct exposure.

Recommendations for Enhanced Security

The campaign also exploited a cloud relay feature to locate and contact cameras using serial numbers. Logs indicate that 89.4% of tested serials connected to channels that bypassed authentication. Attackers generated recovery codes offline, enabling password recovery without current device credentials. This renders the threat more persistent, as eliminating the unauthorized account may not end access.

Organizations are advised to audit all camera accounts, eliminate unauthorized accounts, and frequently change camera and connected recorder credentials. Additionally, administrators should deactivate unneeded P2P features, restrict management services to trusted networks, and apply vendor updates to remedy the bypass vulnerabilities.

Implementing firmware updates is critical as they prevent the generation of new recovery codes and eventually invalidate previous ones. Network and Windows teams should monitor for abnormal login patterns and scrutinize broad security-tool exclusions. For further insights into the risks posed by exposed video equipment, refer to the FBI’s warnings on webcam and DVR attacks and analyses of automated camera exploitation tools.

By staying informed and proactive, organizations can mitigate the risks associated with surveillance equipment vulnerabilities and enhance their overall security posture.

Cyber Security News Tags:authentication bypass, backdoor vulnerabilities, camera exploitation, cloud relay, CVE-2021-33044, CVE-2021-33045, Cybersecurity, Dahua cameras, network security, persistent access, security breach

Post navigation

Previous Post: Critical Exploit Attempts on Super Forms and Elementor Pro
Next Post: Google Patches Critical V8 Zero-Day in Chrome Update

Related Posts

Critical Vulnerability in Carmaker Portal Let Hackers Unlock the Car Remotely Critical Vulnerability in Carmaker Portal Let Hackers Unlock the Car Remotely Cyber Security News
CyberCheck360: Advancing Email Security Beyond Gateways CyberCheck360: Advancing Email Security Beyond Gateways Cyber Security News
Chinese MURKY PANDA Attacking Government and Professional Services Entities Chinese MURKY PANDA Attacking Government and Professional Services Entities Cyber Security News
Bob Flores, Former CTO of the CIA, Joins Brinker Bob Flores, Former CTO of the CIA, Joins Brinker Cyber Security News
Fake Google Page Targets Mexican Bank Users with Malware Fake Google Page Targets Mexican Bank Users with Malware Cyber Security News
Critical WordPress Vulnerability Allows Remote Code Execution Critical WordPress Vulnerability Allows Remote Code Execution Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark