Skip to content
Security & Trust

Hackers probe Ukrainian video recorders using a 2021 flaw, GreyNoise finds

The surge came as Russian strikes grew, GreyNoise says. An unpatched recorder can give outsiders eyes on a site.

W
WebPulse Newsroom
AI-assisted · 3 min read
Share on X LinkedIn
Hackers probe Ukrainian video recorders using a 2021 flaw, GreyNoise finds

Photo: Jan van der Wolf / Pexels

In brief
  • GreyNoise saw scanning and exploitation attempts against Ukrainian video recorders from 21 September to 1 October 2026, mostly using CVE-2021-36260, a Hikvision flaw.
  • An unpatched recorder is a window onto a physical site, so camera patching is a safety question as well as an IT one.
  • Ask who owns recorder patching, which units are exposed to the internet, and whether CVE-2021-36260 is fixed on yours.

A recorder is a window, not just a device

A video recorder sits in a back room and is easily forgotten. Yet it is a networked computer. It shows what is happening at a physical site. If nobody patches it, someone else may be able to watch.

That is the idea behind a new report from GreyNoise, a threat intelligence firm. It describes a rise in scanning and attack attempts against digital video recorders (DVRs) in Ukraine. The activity ran from 21 September to 1 October 2026.

GreyNoise notes that Russia stepped up its strikes in the same weeks. It says a hijacked DVR has many harmful uses. One is watching an area to see what happens before, during and after a strike.

4
Source IP addresses behind the Ukraine activity
Source: GreyNoise (October 8, 2026)

How the flaw works

Most of the activity aimed at CVE-2021-36260. GreyNoise describes it as a way to inject commands into unpatched Hikvision products without logging in.

In plain terms, the device accepts a crafted request and runs the attacker's instructions. "Unauthenticated" means no password is needed. Anyone who can reach the device over a network can try it.

The actors used a ready-made scanning template. It is named "Hikvision IP camera/NVR - Remote Command Execution." That lowers the skill needed. The attacker does not have to write the exploit. They only point the template at addresses.

The word "unpatched" matters. The flaw affects devices that have not been updated. The exposure is a maintenance gap, not a missing defence.

What GreyNoise does and does not say

The traffic came from four addresses. Three were exit points of PureVPN, a commercial VPN service. One sat inside Ukraine.

GreyNoise judges that one entity is behind the PureVPN activity. It links the Ukrainian address to the others only as a possibility, with low confidence.

The firm adds a caution. Many people share a commercial VPN. Some traffic from those exit points may be unrelated.

3
PureVPN exit nodes in the activity
Source: GreyNoise (October 8, 2026)

These four addresses never tried to attack a GreyNoise sensor outside Ukraine. GreyNoise saw almost no similar activity against Ukraine in earlier months. It saw none from these four addresses.

Attempts against CVE-2021-36260 also rose worldwide. The Ukraine-focused pattern stands apart from that wider rise.

The post reports attempts. It does not say how many recorders were compromised. It does not name the actor.

The lesson for organisations far from Ukraine

This is one report about one country over eleven days. It does not show a trend. It does show how to size up a risk: what an unpatched device can see decides how much it matters.

In one setting, a flaw is a nuisance. In another, it is a tool for surveillance. A recorder in a warehouse, clinic or office holds footage of who comes and goes. That detail matters to anyone with a reason to watch.

Cameras are also easy to overlook. Facilities teams or outside installers may buy and fit them. If so, they can fall outside the normal patching routine. That is a gap in ownership, not just in software.

Questions to put to your team

Start with an inventory. Do we know every video recorder and network camera we run? Include those fitted by vendors or facilities staff.

Then check exposure. Are any Hikvision units on the list? Are they patched against CVE-2021-36260? Can any be reached from the internet?

Finally, settle ownership. Who must update these devices: IT, facilities or the installer? If the answer is unclear, that is the finding.

21 Sep – 1 Oct 2026
Window of observed activity
Source: GreyNoise (October 8, 2026)

An unpatched camera keeps recording for its owner. The risk is that someone else can watch too.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: GreyNoise.

Share this insight