From streets to supply lines: the unforeseen risks of exposed IP cameras

|
Updated

A recent news article highlighted an all-too-familiar story: publicly exposed IP cameras have once again been successfully targeted to help enable nation states in their war efforts. The article references a cybersecurity advisory released by the Netherlands General Intelligence and Security Service (AIVD) and the Netherlands Defence Intelligence and Security Service (MIVD). It warns various EU, NATO member states, and Ukraine that Russian state actors are “systematically conducting digital espionage operations via IP cameras (cameras with internet access).”

In recent years, we have seen cameras hacked to enable one country to target another, and this new evidence indicates that Russia is using hacked cameras to track NATO troop and supply movements. While it isn’t surprising that nation states are finding and exploiting novel techniques to enable their combat effectiveness, it is concerning that IP camera exploitation continues to be so easy.

It’s also interesting and worrisome that the IP cameras that are often being targeted are not owned and operated by defense forces, but are a part of civilian infrastructure. While the intended surveillance targets of the hacked cameras are defense personnel, supply lines, and logistics infrastructure, the source of the data is from everyday cameras on buildings, street corners, and even homes. Unfortunately, many organizations have limited or no visibility into their IP cameras, or their security (or lack thereof). These devices offer not only the perfect tool to spy on your adversary, but also the perfect pivot point for full network exploitation.

The scale of the problem #

According to the article, Censys discovered “87,000 internet-connected cameras running a service whose version matches a known-exploited vulnerability” across the EU with over 4,000 of them in the Ukraine. The Censys researcher was careful to clarify that a camera being exposed to the internet, even if it has a CVE or if it’s on the KEV list, does not automatically mean it is hackable or being actively accessed by malicious cyber actors. While this is an important point, we know that CVEs are often not the entry points used by cyber threat actors. For example, default logins allow for easy to gain yet hard to detect access, providing a preferable method for entry.

One important fact not covered in the advisory is that the most prolific IP camera manufacturers, which are banned for use by any U.S. government entity because of their potential ties to the Chinese government, are consistently purchased by non-government entities within the United States and other Allied nations. And while statistics aren’t available for the number of U.S. commercial entities, let alone private citizens, who own and use these risky IP cameras, the number is undoubtedly high. Factor in that these cameras use or expose UPnP, an often and easily abused protocol, and you’ll discover that the U.S., and other countries, are target rich environments for cyber threat actors.

Close the lens: How runZero helps protect against IP camera abuse #

While we don’t expect the abuse of IP-enabled cameras to stop anytime soon, the good news is that the cybersecurity advisory offers some simple yet effective guidance on how to protect these devices:

  • Identify and discover what is exposed to the internet, either directly or indirectly through something like a proxy, firewall, or vendor cloud relay.
  • Disable the stream from the internet; disable port forwarding and UPnP. Configure camera access through a VPN.
  • Disable or change default credentials and enable MFA where possible.
  • This is likely harder for non government entities, but if possible, angle the cameras away from logistics routes, loading docks, and other sensitive areas.
  • Patch firmware and software regularly, and purchase products with extended support lifecycles.

runZero can help address the security issues presented by IP-enabled cameras in a few ways:>

  • You need to know everything on your network, not just IP cameras. runZero can discover and identify everything on your network, including IP cameras and let you know whether they are public-facing or not.

  • runZero knows all about UPnP. We provide UPnP discovery network-wide, allowing you to close down any potential initial or lateral movement opportunities for adversaries.

  • Just because a camera is present doesn’t mean it's problematic. However, IoT devices are oftentimes unknowingly or unintentionally connected to networks they shouldn’t be. runZero can help to visualize and discover segmentation gaps, multi-homed devices, or simply misplaced devices.

If you aren’t certain that your attack surface, including your IP-enabled cameras, is properly protected, especially in the era of AI-enabled attacks, contact us today or sign up for a free trial.

Written by Colin Dupreay

Colin is a Federal Solutions Engineer at runZero. With almost a decade of experience supporting Public Sector customers, Colin is passionate about protecting and securing our nations networks.

More about Colin Dupreay
Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.

Explore more runZero

Product
runZero 5.1 is here: Secure AI workflows, enhanced integrations, and expanded autonomous discovery
runZero 5.1 takes on the heavy lifting across five key areas, enabling you to unmask and remediate exposures with less friction and more speed.
Podcasts
Know Your Adversary with HD Moore
runZero CEO HD Moore breaks down the myth of air-gapped networks, the impact of AI on security, and why asset connectivity is everything.
runZero Perspective
BOD 26-04: A new era of prioritized remediation
A complete breakdown of CISA's BOD 26-04 directive. Learn how the shift to SSVC, risk-based KEV prioritization, and 3-day remediation impacts your...
runZero Perspective
Dawn of the apex agentic adversary
When agentic AI can weaponize exploits in seconds, visibility is everything. Stop the predator with runZero’s exposure management for the AI-attack...
Webcasts
runZero Hour, Ep. 33: Hacker Summer Camp: we survived the Vegas heat (and the bugs)
In this post-Hacker Summer Camp recap, the runZero team break down the research, tools, and trends discussed at BSides Las Vegas, Black Hat and DEF...
Podcasts
The Internet's biggest point of failure
Join Tod Beardsley on Secure & Scale as he explores the future of vulnerability management, CVE fragmentation, and how AI is changing security...
Webcasts
Mind the gaps: securing the modern IT/OT attack surface
In this webcast, HD Moore and GigaOm Analyst Chris Ray discuss key methods for hardening OT defenses and share insights from the new OT report.
Webcasts
runZero Hour, Ep. 32: AI-pocalypse now? Why the 2026 DBIR is actually good news
In this episode of runZero Hour, Tod Beardsley, Brianna Cluck, and Verizon's Alex Pinto broke down 2026 DBIR trends, AI threats, and runZero 5.0.

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.