<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Credential-Attack on CuraSec</title><link>https://curasec.metacog.co.kr/tags/credential-attack/</link><description>Recent content in Credential-Attack on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 20 Aug 2026 11:39:11 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/credential-attack/index.xml" rel="self" type="application/rss+xml"/><item><title>14,500 Dahua IP cameras compromised in 35-day CameraSwarm campaign</title><link>https://curasec.metacog.co.kr/insights/2026-08-20-hackers-compromise-14-500-dahua-web-cameras-in-35-day-campai/</link><pubDate>Thu, 20 Aug 2026 11:39:11 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-20-hackers-compromise-14-500-dahua-web-cameras-in-35-day-campai/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If Dahua cameras are in scope, audit all units for default or weak credentials and remove any direct internet exposure; the campaign scale suggests opportunistic credential stuffing across this device class, but no KEV or PoC shifts this below Act.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs or ATT&amp;amp;CK-mappable TTPs are surfaced in this item, and the compromise is geographically concentrated in Ukraine and Russia — limited detection work is actionable for a typical enterprise SOC without more detail.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Operation CameraSwarm: 14,500+ Dahua Devices Compromised via Auth Bypasses</title><link>https://curasec.metacog.co.kr/insights/2026-08-20-hackers-compromised-14-500-dahua-devices-using-credential-at/</link><pubDate>Thu, 20 Aug 2026 11:39:11 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-20-hackers-compromised-14-500-dahua-devices-using-credential-at/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> If your environment includes Dahua cameras or NVRs, audit for these two auth-bypass CVEs and enforce credential rotation immediately; also review whether P2P relay features are exposed to the internet and disable if not required.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build detections for unusual outbound P2P relay traffic from camera subnets and sweep network logs for connections to Dahua cloud relay infrastructure since June 17, 2026; full IOC set not confirmed in enrichment signals but Hunt.io research may provide indicators.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Large-scale IoT compromise campaign is worth noting for vendor risk assessments if Dahua devices are deployed in physical security infrastructure, but no immediate leadership action is required absent confirmed breach at your organization.&lt;/li>
&lt;/ul></description></item></channel></rss>