CuraSec

tag: Credential-Attack · 2 items

  • Engineer — Act: If your environment includes Dahua cameras or NVRs, audit for these two auth-bypass CVEs and enforce credential rotation immediately; also review whether P2P relay features are exposed to the internet and disable if not required.
  • SOC/IR — Plan: Build detections for unusual outbound P2P relay traffic from camera subnets and sweep network logs for connections to Dahua cloud relay infrastructure since June 17, 2026; full IOC set not confirmed in enrichment signals but Hunt.io research may provide indicators.
  • Leader — Learn: Large-scale IoT compromise campaign is worth noting for vendor risk assessments if Dahua devices are deployed in physical security infrastructure, but no immediate leadership action is required absent confirmed breach at your organization.
2026-08-20 · BleepingComputer · source ↗ #iot-security#credential-attack#camera
  • Engineer — Plan: If Dahua cameras are in scope, audit all units for default or weak credentials and remove any direct internet exposure; the campaign scale suggests opportunistic credential stuffing across this device class, but no KEV or PoC shifts this below Act.
  • SOC/IR — Learn: No IOCs or ATT&CK-mappable TTPs are surfaced in this item, and the compromise is geographically concentrated in Ukraine and Russia — limited detection work is actionable for a typical enterprise SOC without more detail.
  • Leader — Skip