By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Hackers Compromised 14,500+ Dahua Devices

Cybersecurity researchers at Hunt.io have detailed a campaign, codenamed Operation CameraSwarm, that successfully compromised over 14,530 Dahua devices. This extensive compromise occurred between June 17 and July 22, 2026, and leveraged a combination of credential stuffing attacks, two specific authentication-bypass vulnerabilities, and a peer-to-peer (P2P) relay technique. The findings were reconstructed from a substantial 407 MB exposed working directory, which contained 2,616 files, providing researchers with a granular view of the attackers' methods and the scope of the breach. Dahua Technology is a global manufacturer of video surveillance products, including video management software, video analytics, and access control systems, making its devices a frequent target for malicious actors seeking to infiltrate networks or conduct surveillance.
The attackers employed a multi-pronged approach to gain unauthorized access. Credential stuffing involves using lists of usernames and passwords stolen from previous data breaches to attempt logins on new systems. This method is effective when users reuse credentials across multiple platforms. The two authentication-bypass flaws identified allowed attackers to circumvent security measures designed to verify user identity, granting them access without proper authorization. The use of a P2P relay technique suggests a sophisticated method for maintaining persistence and potentially evading detection by routing traffic through multiple compromised devices, creating a distributed network of command and control points. This technique can obscure the origin of malicious commands and make it harder to trace the attackers.
Operation CameraSwarm's impact highlights significant security weaknesses in connected devices. The sheer volume of compromised devices, exceeding 14,500, indicates a widespread vulnerability or a highly effective exploitation campaign. The exposed working directory, containing 2,616 files, likely includes logs, configuration details, and potentially evidence of further malicious activities, such as data exfiltration or the deployment of additional malware. The researchers' reconstruction of the campaign from this data underscores the importance of secure development practices and timely patching of vulnerabilities by device manufacturers like Dahua. The findings were made public to alert users and encourage immediate security remediation efforts.
The campaign's timeline, spanning just over a month from mid-June to late July 2026, suggests a rapid and efficient exploitation process. The specific nature of the attacks—credential stuffing and authentication bypasses—points to attackers targeting weak or default credentials and exploiting known or newly discovered security flaws. The P2P relay technique further indicates a level of technical proficiency aimed at maintaining covert access and potentially expanding the compromised network. Hunt.io's disclosure serves as a critical warning to organizations and individuals utilizing Dahua devices, emphasizing the need for robust security protocols, including strong, unique passwords, regular firmware updates, and network segmentation to limit the potential damage from such breaches.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.