CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4695

As cited

Copy frozen at (site build).

threat intel

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

Researchers at Hunt.io documented a campaign called Operation CameraSwarm that compromised over 14,500 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass vulnerabilities, and a peer-to-peer relay technique. The analysis drew from a 407 MB exposed working directory containing 2,616 files.

Why it matters: Organizations deploying Dahua cameras and devices need to audit their installations for signs of compromise, reset credentials, and apply authentication patches immediately, as this campaign demonstrates active exploitation at scale.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

Researchers at Hunt.io documented a campaign called Operation CameraSwarm that compromised over 14,500 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass vulnerabilities, and a peer-to-peer relay technique. The analysis drew from a 407 MB exposed working directory containing 2,616 files.

Why it matters: Organizations deploying Dahua cameras and devices need to audit their installations for signs of compromise, reset credentials, and apply authentication patches immediately, as this campaign demonstrates active exploitation at scale.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

Researchers at Hunt.io documented a campaign called Operation CameraSwarm that compromised over 14,530 Dahua devices between June 17 and July 22, 2026. The attackers exploited credential attacks, two authentication-bypass vulnerabilities, and a peer-to-peer relay method, with evidence reconstructed from an exposed 407 MB working directory containing 2,616 files.

Why it matters: Organizations using Dahua devices must investigate for compromise indicators within the attack window and patch authentication-bypass flaws immediately; credential attacks suggest weak or reused passwords require review and rotation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary