The images in this article were generated with artificial intelligence. How we publish
A joint notice from the Dutch intelligence services has replaced a reality that has been growing for years: Internet-connected surveillance cameras are vectors of practical intelligence and sometimes of concrete attacks. It is not a spectacular intrusion through an unpublished vulnerability, but rather a much more prosaic and effective thing: devices accessible from the public network, with default credentials, unupdated firmware or configurations that expose real-time images to anyone who finds them.
What changes the game against the old image of the "indiscreet eye" is automation. Today there are engines that scan the global network to identify cameras by software footprint and version, and then apply image recognition to detect patterns of interest - military trucks, containers, plates - without continuous human intervention. This makes a camera a remote sensor for logistical and geo-strategic monitoring, and in certain cases an auxiliary tool for kinetic attacks, as the services in Ukraine have documented.

Preliminary figures of researchers mapping the exposed area suggest that we speak of tens of thousands of publicly attainable cameras in Europe and neighbouring countries, with several thousand in conflict areas. That magnitude explains why intelligence teams prefer to exploit the obvious: open doors, not secret doors. In addition, once an attacker has control of the host that houses the camera, it does not need zero-day vulnerabilities to scale or move laterally.
The implications are double and urgent. First, there is a tactical aspect: live images allow you to decide when to mobilize resources, when to empty a dock or when to stop a convoy. Secondly, there is a strategic and civil risk: the same exposure that allows to monitor military routes also filters commercial movements, staff presence, shift habits and other useful signals for industrial or criminal espionage. In both cases, the solution is not unique or technological: it requires operational habits and design decisions in the physical and network safety infrastructure.
For organizations and managers, the first commitment is inventory and prioritization. Identify which cameras are accessible from the Internet and which point to sensitive assets should be the first task, followed by examining access records for abnormal connections. It is not enough to know that a device is responding; it is necessary to know what it looks at and what damage it could cause that observation in the hands of others.
The specific measures that reduce the risk are simple and proven: avoid direct exposure to the public network by removing mapping from ports and UPnP rules, access to cameras through VPN or authenticated tunnels, replace default credentials and enable multifactor authentication if supported by the device, patch firmware regularly and, where this is not possible, remove the camera from any external access. From the physical point of view, it is effective to limit the field of view so that it does not include logistical routes, docks or entry areas, and to use cover or masking on sensitive areas that cannot be removed from the frame.
There are also medium-term purchase and architecture decisions that make the difference: prioritizing devices with long-term security support and regular updates, requiring the supplier to have clear policies to respond to vulnerabilities, segmenting the network with VLans and access control lists so that a compromised camera is not a gateway to other systems, and using telemetry and alert tools that reveal unusual access or bandwidth peaks.

For environments with legacy equipment that cannot be replaced immediately, there are reasonable compensatory controls: placing the cameras in an isolated subnetwork with limited internet output, applying IP filtering in the gateways, monitoring outgoing connection patterns and deploying intrusion detection systems that monitor unusual RTSP / HTTP traffic. In all cases, coordination with the national CERT or the security provider can accelerate mitigation in active incidents.
The phenomenon is not exclusive to war; the same technique serves for industrial surveillance, monitoring critical infrastructure and influence campaigns. It is therefore relevant to review the catalogue of known vulnerabilities and prioritize patches. Public resources such as the catalogue of vulnerabilities exploited by CISA active threats https: / / www.cisa.gov / knowledge-exploited-vulnerabilities-catalog or the CVE technical data sheets in the NIST https: / / nvd.nist.gov / vuln / detail / CVE-2016-7407 and https: / / nvd.nist.gov / vuln / detail / CVE-2021-39275 are useful starting points to understand which versions and components should be updated. Researchers who map the public surface, such as the https: / / censys.io they also publish findings that help to size the problem in each country.
In short, the lesson is clear: camera exposure is not a theoretical risk but an operational vulnerability used by sophisticated actors with resources to automate image collection. The good news is that countermeasures are, for the most part, common sense and cost-effective: to eliminate public access when it is not necessary, to strengthen authentication, to apply patches and to segment the network. Those who manage physical surveillance should move from considering cameras as isolated elements to integrating them into the organization's cybersecurity strategy.
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...