There was a rise in scanning and remote code execution attempts on video surveillance devices in Ukraine from September 21 to October 1, 2026.
Most work was on CVE-2021-36260, a serious command injection flaw in unpatched Hikvision products. The increase happened during Russian missile and drone strikes, but researchers have not found a link between the cyber work and those attacks.
The results show that people are interested again in an old weakness that allows attackers to take control of open cameras and recording gear without logging in. GreyNoise’s observations show attempts to exploit, not actual takeovers of surveillance systems. This difference is important when looking at the campaign’s effects and goals.
Hikvision Camera Vulnerability
According to GreyNoise’s timeline, on September 21, someone checked on a Ukrainian network by trying to connect to service ports without using an exploit.
Exploitation attempts went up a lot on September 23 and kept rising until October 1. This made a nine-day increase after months of very little activity against Ukraine. Four IP addresses made up almost all the attempts during the spike. Three were from PureVPN exit nodes, and the fourth was from a local Ukrainian network.

One group caused the VPN activity, but GreyNoise is not very sure the Ukrainian address is connected to it.
The VPN addresses were 195.238.124.178, 195.238.124.181, and 195.238.124.188, linked to AS56630 in Lithuania. Commercial VPN exits can be used by different users, so these indicators alone should not be seen as proof of a common operator. The Ukrainian address was not named publicly.
GreyNoise saw more scanning worldwide for the flaw, but these four addresses didn’t try to exploit its sensors outside Ukraine. Every request from the group used the same command test and had no installation payload. No other attempts from those addresses were seen through October 7.
CVE-2021-36260 impacts the web server in some Hikvision products. Bad input checks let harmful requests with malicious commands get to the device’s operating system. NIST gives this vulnerability a high CVSS score of 9.8, showing it can be exploited over a network without needing to log in or interact with a user.
The activity looked at the Nuclei template called “Hikvision IP camera/NVR – Remote Command Execution.” This shows automated tests for weaknesses, not that hackers put in malware or accessed video. GreyNoise’s tests back up this simpler view.
Compromised cameras can show secret locations and actions. In January 2024, Ukrainian officials said they turned off two cameras that Russian spies had hacked to watch Kyiv’s air defenses and buildings. This past case shows the danger; it does not say who did this new attack.
Administrators need to find the affected models and use Hikvision’s firmware updates as suggested by CISA. Limiting public access and keeping surveillance equipment separate from important networks can lower risks while updates are being made. Just changing passwords won’t fix the flaw that allows unauthorized command injections.
InfoSecBulletin Cybersecurity for mankind
