Visualização de leitura

Como se proteger da espionagem por webcam: cinco passos simples

Hoje, pode parecer que há uma câmera nos observando em cada canto: na campainha com vídeo na entrada, na webcam de um notebook no escritório de casa, na babá eletrônica IP no quarto das crianças, na smart TV com câmera e microfone no quarto, no robô aspirador com câmera de navegação… Até um alimentador inteligente para gatos pode estar espionando você! E qualquer uma dessas câmeras pode facilmente se transformar em uma ferramenta de extorsão, chantagem ou curiosidade mal-intencionada.

Nem é preciso procurar muito para encontrar exemplos. Coreia do Sul, final de 2025: não foi apenas um dispositivo, mas 120.000 câmeras IP foram invadidas. Os criminosos vendiam, por assinatura em chats privados, imagens íntimas e gravações do cotidiano das pessoas.

Neste artigo, analisamos exatamente de onde vem a ameaça e apresentamos cinco regras que podem reduzir bastante as chances de você virar a estrela do show de um voyeur.

Casos reais de vigilância

Pornografia de hotel por assinatura

Infelizmente, relatos sobre câmeras em miniatura encontradas em quartos de hotel e apartamentos alugados se tornaram quase rotineiros. Tecnicamente, elas pertencem a uma categoria diferente de dispositivos: “câmeras espiãs” disfarçadas de tomadas, detectores de fumaça ou despertadores. Mais adiante, explicaremos como detectá-las.

Os criminosos não se limitam a publicar imagens de câmeras espiãs. Também fazem transmissões ao vivo. O acesso a vídeos íntimos, naturalmente, não é gratuito. Em algumas regiões, criminosos montaram uma infraestrutura em torno das câmeras espiãs: uns instalam os dispositivos, outros processam as imagens e outros vendem o acesso pela dark web ou por aplicativos de mensagens. Em geral, as vítimas descobrem que havia uma câmera oculta no quarto do hotel por acaso, depois de se depararem com vídeos de si mesmas em sites pornográficos.

Caça a motoristas

Outro vetor de ataque comum é a invasão de câmeras veiculares conectadas à Internet. Esses dispositivos são alvos atraentes para invasores: a segurança é fraca, e as imagens mostram claramente placas de veículos, sinalização viária e endereços em prédios. As gravações também contêm metadados detalhados, incluindo datas exatas, coordenadas de GPS e outras informações.

Isso pode permitir que criminosos identifiquem as rotas habituais da vítima, descubram onde o carro fica estacionado ou até escutem conversas com passageiros. As informações podem ser suficientes para uma vigilância completa, o roubo do veículo ou até chantagem, caso a câmera grave conversas e imagens dentro do carro.

Stalking

Nem todas as imagens roubadas de câmeras resultam de ataques de cibercriminosos profissionais em busca de lucro. Às vezes, stalkers invadem webcams para espionar pessoas específicas, muitas vezes alguém que conhecem. Por exemplo, em 2025 veio à tona um caso em que um homem vinha espionando colegas de trabalho havia anos por meio das câmeras IP instaladas nas casas delas. Todas as vítimas eram mulheres, e não faziam ideia de que estavam sendo observadas.

Em outro caso, um homem monitorava a ex-esposa e a filha por meio de um sistema de interfone e câmeras IP. Ele nem tentava esconder que espionava a própria família e chegou a enviar à filha capturas de tela da webcam. Como consequência, ela acabou tendo que se mudar.

Por que isso acontece?

Negligância com regras básicas de cibersegurança

Esse é provavelmente o principal motivo pelo qual câmeras IP são invadidas. A maioria dos usuários não altera senhas padrão de roteadores, dispositivos inteligentes e aplicativos conectados a eles. Essas senhas são praticamente de conhecimento público. Muitas vezes, são usadas combinações simples, como “admin/admin” ou “root/1234”, que todos conhecem ou que podem ser adivinhadas em segundos sem um algoritmo sofisticado. Foi exatamente isso que permitiu aos invasores comprometer 120.000 câmeras na Coreia do Sul.

Fabricantes de câmeras irresponsáveis

Embora os fabricantes garantam que os dados das câmeras sejam armazenados apenas localmente, na prática, costuma ser bem diferente. Por exemplo, em 2022, pesquisadores descobriram que uma linha popular de câmeras de vídeo enviava capturas de imagem ao servidor do fabricante sempre que uma pessoa aparecia no quadro. E mais: o acesso remoto às gravações de todas as câmeras ficava disponível por URLs previsíveis, o que tornava essas URLs relativamente fáceis de reproduzir ou adivinhar.

Ao mesmo tempo, a empresa afirmava que suas câmeras usavam criptografia de ponta a ponta, armazenavam gravações apenas no dispositivo e não enviavam dados a servidores externos. Por sinal, a suposta “criptografia segura” era implementada com uma chave fixa idêntica para todos os usuários. E a própria chave podia ser facilmente encontrada no código-fonte publicado pelo fabricante.

Em resumo, se um dispositivo tem lente e Wi-Fi, considere a possibilidade de que, mais cedo ou mais tarde, uma falha grave de segurança seja descoberta nele.

Mecanismos de busca para dispositivos vulneráveis estão se tornando cada vez mais populares

Para acessar uma câmera, muitas vezes o invasor só precisa saber o endereço IP dela e testar algumas senhas comuns. Existem mecanismos de busca que indexam dispositivos e suas portas abertas, em vez de sites: webcams, roteadores, controladores industriais, equipamentos médicos e muito mais.

Se uma câmera IP não exigir nome de usuário e senha ou estiver “protegida” pelas credenciais padrão “admin/admin”, ela pode ser facilmente descoberta e adicionada ao banco de dados de um serviço de OSINT. Jornalistas e pesquisadores já usaram esses serviços para encontrar câmeras acessíveis ao público em quartos de crianças, escritórios, salas cirúrgicas de hospitais, bancos e lojas.

Então, o que fazer?

O que é possível fazer em casa ou em um pequeno escritório sem uma equipe dedicada à segurança? Estas cinco recomendações simples podem ajudar.

1. Pesquise sobre o fabricante

Ao escolher um modelo de câmera IP, verifique se câmeras daquele fabricante já foram invadidas. Por exemplo, pesquise por “invasão de câmera IP nome do fabricante“. Depois, acesse a seção de Suporte do fabricante e confira a data da atualização de firmware mais recente para o modelo considerado e para modelos mais antigos.

Se o firmware não tiver sido atualizado nos últimos seis meses ou se as atualizações forem lançadas de forma irregular, considere escolher outro modelo. A maioria das câmeras usa versões embarcadas especializadas do Linux, e mais de 2.300 vulnerabilidades foram registradas no kernel do Linux nos primeiros seis meses de 2026. Sem atualizações regulares de firmware, é quase certo que, mais cedo ou mais tarde, as câmeras de um fabricante apresentarão uma falha de segurança.

Considere modelos de grandes fabricantes para evitar uma coleção inteira de vulnerabilidades com praticamente nenhuma chance de que elas sejam corrigidas. Câmeras baratas de empresas pouco conhecidas, com recursos limitados e proteção fraca, podem acabar saindo caras.

2. Desative recursos desnecessários

Quanto menos serviços de armazenamento em nuvem de terceiros estiverem envolvidos no sistema de vigilância, melhor. Ao escolher uma câmera, procure um slot para cartão microSD ou compatibilidade com dispositivo de armazenamento conectado à rede (NAS), para que todas as gravações possam ser armazenadas localmente.

O ideal é que a câmera consiga funcionar na rede local, sem transmitir dados para a nuvem ou para os servidores do fabricante, com visualização pela LAN ou por meio de uma conexão segura com a rede doméstica ou do escritório.

Ao comprar outros dispositivos para casa inteligente, avalie se você realmente precisa de uma câmera integrada à smart TV, caixa de som inteligente, robô aspirador ou alimentador automático para animais. Cada um desses dispositivos amplia a superfície de ataque em potencial.

Depois de comprar uma câmera IP, revise as configurações, geralmente disponíveis no aplicativo do fabricante ou pela interface Web da câmera, e desative tudo o que não for necessário.

  • Preste atenção aos recursos relacionados ao reconhecimento de pessoas, inteligência artificial, permissões do sistema, descoberta de outros dispositivos na rede e armazenamento em nuvem. Se você não usa um recurso, pode desativá-lo.
  • Nas configurações de rede, confirme que o UPnP (Universal Plug and Play) está desativado ou sequer disponível como opção. O UPnP pode permitir que a câmera se torne acessível a outros dispositivos pela Internet.
  • Verifique se o acesso P2P à webcam está desativado ou indisponível, para que a câmera não se conecte a servidores externos nem possa ser acessada pela Internet sem seu controle direto.
  • Crie o hábito de verificar quem está conectado à sua conta e quem ainda tem acesso às suas gravações. Se você concedeu acesso à webcam a um amigo para ficar de olho no seu cachorro durante uma viagem, lembre-se de revogar depois os acessos ou encerrar as sessões desnecessárias. E, se você terminou um relacionamento recentemente, verifique com atenção especial se a pessoa com quem se relacionava ainda tem acesso. Para saber mais, consulte Higiene digital após uma separação: o que verificar e desativar.

3. Altere as configurações padrão

As senhas padrão de fábrica são conhecidas pelos invasores há anos. Se você ainda não alterou o nome de usuário e a senha do roteador ou da câmera IP, um invasor pode conseguir acesso em questão de segundos.

  • Substitua o nome de usuário e a senha padrão de fábrica do roteador por credenciais exclusivas e longas. Isso pode ser feito pela interface Web do roteador. Explicamos abaixo como acessá-la. Para gerar e armazenar senhas fortes e exclusivas, recomendamos usar Kaspersky Password Manager.
  • Se a câmera estiver vinculada a uma conta em um site ou aplicativo, use também uma senha forte e ative a autenticação de dois fatores ou a autenticação por chave de acesso sempre que possível. Os tokens de 2FA e as chaves de acesso também podem ser armazenados no Kaspersky Password Manager e sincronizados em todos os seus dispositivos.
  • Atualize o firmware do roteador e da câmera IP para as versões mais recentes, mesmo que você tenha acabado de comprar os dispositivos, e crie o hábito de fazer atualizações regularmente. Campanhas de invasão de câmeras IP em grande escala muitas vezes exploram vulnerabilidades conhecidas há muito tempo, que só podem ser corrigidas com a instalação de atualizações.

4. Coloque todas as câmeras e dispositivos inteligentes em uma rede Wi-Fi separada

Recomendamos segmentar o Wi-Fi doméstico em sub-redes separadas. Você provavelmente já viu essa configuração em cafés, que costumam ter uma rede Wi-Fi para a equipe e outra para visitantes.

O ideal é colocar todas as câmeras IP e outros dispositivos de casa inteligente em uma rede Wi-Fi separada e totalmente isolada de notebooks, celulares e outros dispositivos de trabalho. Melhor ainda, as câmeras IP devem ficar isoladas de todos os demais dispositivos em uma rede Wi-Fi dedicada exclusivamente a elas.

A maioria dos roteadores modernos permite criar pelo menos duas redes Wi-Fi, uma rede principal e uma rede para visitantes. Modelos mais avançados podem oferecer ainda mais opções. Assim, mesmo que a câmera seja invadida, o invasor não conseguirá chegar aos outros dispositivos nem acessar arquivos confidenciais.

Como abrir a interface Web do roteador

  1. Digite o endereço IP do roteador na barra de endereços do navegador. Normalmente, ele está impresso em uma etiqueta na parte inferior do roteador. Entre os endereços IP comuns para roteadores domésticos estão 168.0.1, 192.168.1.1 e 10.0.0.1.
  2. Na página que abrir, faça login. A maioria dos roteadores tem um nome de usuário e uma senha padrão, que normalmente também estão impressos na mesma etiqueta. Alguns roteadores podem solicitar a criação de um nome de usuário e de uma senha. Recomendamos escolher uma senha forte e armazená-la no Kaspersky Password Manager. As senhas padrão de fábrica são conhecidas pelos invasores há muito tempo e, se você não alterar a senha do roteador, eles podem entrar facilmente na sua rede doméstica.
  3. Abra as configurações e procure seções relacionadas à segmentação da rede Wi-Fi ou à criação de sub-redes ou redes para visitantes.

Para obter instruções detalhadas de configuração, consulte o manual do roteador ou a seção de suporte do site do fabricante. Para mais dicas sobre como proteger sua casa inteligente, consulte nossa postagem Como proteger sua casa smart.

5. Aprenda a detectar câmeras ocultas, em casa e durante uma viagem

Nosso último conjunto de recomendações não trata da configuração da câmera em si, mas de boas práticas de segurança.

Crie o hábito de verificar a lista de clientes do roteador. Se você vir um dispositivo desconhecido com um nome estranho ou endereço MAC, investigue o que é e por que está conectado à sua rede doméstica. Nossa solução de segurança inclui um componente dedicado do Smart Home Monitor. Esse recurso pode alertar quando um novo dispositivo se conecta à rede doméstica com ou sem fio, fornecer recomendações simples para melhorar a segurança da rede e identificar senhas fracas do roteador e criptografia insegura.

Durante viagens, recomendamos verificar se há dispositivos de gravação ocultos em quartos de hotel e imóveis alugados:

  • inspecione locais que ofereçam um bom campo de visão do ambiente, como grades de ventilação, detectores de fumaça, tomadas e objetos decorativos;
  • no escuro, use o smartphone como detector óptico improvisado: ligue a lanterna e a câmera, examine lentamente o ambiente e procure reflexos característicos produzidos por lentes de câmeras;
  • use a câmera frontal para procurar fontes de luz infravermelha invisíveis ao olho humano. Isso pode ajudar a identificar a iluminação IR usada para “visão noturna”.

Para conhecer outros métodos práticos de encontrar câmeras espiãs, consulte nosso post Quatro maneiras de encontrar câmeras espiãs.

O que mais você deve saber sobre vigilância e câmeras:

Slovakia Warns of Cyber Risks in Road Speed Cameras

Slovakia warns that vulnerable speed cameras could expose vehicle data, enable remote access and provide attackers with a foothold into public networks.

Slovakia’s National Security Authority, NBÚ, recently issued a warning about several road speed cameras, calling them a significant cyber threat. The alert is not about someone deleting a speeding ticket. It is about connected devices that collect vehicle data, communicate with other systems, and may contain remote-access functions that the operator cannot fully control.

The Slovak authority examined a sample of the NERO R-ONE camera system at the request of the Interior Ministry. It named three product lines in its warning: NERO R-ONE devices sold by Cyprus-based SODASUS, Cordon-series speed cameras made by Russia’s Simicon, and Cordon-series products sold by Croatia’s NEROline.

“The National Security Authority warns of a significant cyber threat associated with the use of several types of road speed cameras.” reads the alert. “A security analysis has identified several risks and recommends that affected entities identify the products in question in their infrastructure.”

The problems went beyond a simple configuration issue. NBÚ found differences between the documented and actual communication settings, uncertainty about where the hardware and software came from, software that did not match the declared version, and weak security protections.

“The security analysis identified several risks, including the true origin of the camera hardware and software, inconsistency between the documented and detected configuration of the product’s communication interfaces, and pre-configured remote access and product management mechanisms.” the agency wrote on LinkedIn.

That last point deserves attention. A road camera should be managed by the organisation that owns it, under controls that it can inspect, configure and audit. If a device includes pre-set remote-access or management mechanisms outside the customer’s full control, it creates a blind spot in a system that may sit on a public-sector network or communicate with other operational services.

Speed cameras do much more than take pictures and measure speed. They photograph vehicles, record timestamps, process licence-plate data, store evidence and send information to backend systems used by authorities. Depending on the setup, they may also connect to mobile networks, roadside equipment, police systems, municipal platforms or third-party maintenance services.

If attackers compromise a camera, they could access data, change or delete records, manipulate how it measures or reports violations, or shut it down. If the network lacks proper segmentation, they could also use the camera as a foothold to reach other systems. The camera may not be the real target. It could simply be the unlocked door.

The warning aims to alert essential-service operators and other organisations that these road cameras could pose a serious cybersecurity risk. In the wrong circumstances, attackers could use them to disrupt networks, systems or services.

The Slovak Interior Ministry reportedly took the equipment out of its pilot deployment while the matter was investigated. Public reporting also says the ministry asked the supplier to remove the units and replace them with equipment meeting Slovak and EU legal, technical and security requirements.

The Russian connection adds an obvious geopolitical dimension, but it should not become a substitute for technical analysis. NBÚ did not say that every device was actively spying on users or that the equipment contained a proven backdoor. Its warning is about identified security risks, limited operator control, uncertainty over hardware and software provenance, and remote-management mechanisms that could not be fully accounted for.

That is enough reason to take action. Security checks for connected public devices cannot rely only on the brand, the country listed on the invoice or the vendor’s claims. Operators should know exactly what software and firmware the device runs, how remote access works and who controls it. They should also use independent security testing, secure updates and network segmentation.

The same lesson applies beyond Slovakia. Smart cameras, licence-plate readers, parking sensors, environmental monitors, traffic lights and roadside communication systems are becoming part of public infrastructure. They are often cheap, easy to overlook and managed by public agencies, contractors and manufacturers. That makes them just as important to secure as other critical systems.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Speed Cameras)

Inside Operation CameraSwarm: How One Actor Took Over 14,000 Dahua Cameras

An exposed operator directory reveals how one actor compromised 14,000+ Dahua cameras across Ukraine and Russia, no password needed for most.

A researcher discovered an exposed directory containing the tools of an attacker who compromised more than 14,000 Dahua cameras between June 17 and July 22, 2026, mainly in Ukraine and Russia. Hunt.io reconstructed the operation, named Operation CameraSwarm, from the leaked files and telemetry.

The find started with a mistake. On 23 July, Hunt.io’s AttackCapture system crawled a server at 154.86[.]119.60 and pulled down 2,616 files across 234 subdirectories, 407 MB in total, from an HTTP directory the operator had left wide open. That single slip handed researchers the operator’s scanning engine, exploit chains, exfiltration bot, and a Windows stealer staged on the same box.

“This is the second Dahua-related camera compromise operation we’ve traced back to an exposed operator directory in as many weeks. Where last week’s investigation centered on a Russian-speaking operator running a purpose-built platform against 58 cameras, this one is a different scale entirely.” reads the report published by Hunt.io.

The brute-force engine alone reached over 12,300 unique addresses. A separate authentication-bypass chain, built around two 2021 Dahua vulnerabilities, planted a persistent backdoor account on 1,923 cameras, an account stored independently of the admin password that survives both a password change and, on most firmware, a factory reset. A third path skipped IP addresses entirely and reached 283 cameras purely by serial number, through Dahua’s own cloud relay.

That third path is the part worth sitting with. Most of those cameras were exposed online without authentication.

Dahua’s cloud relay lets any app reach a camera sitting behind NAT using nothing but its serial number, and authentication to that relay runs on credentials baked identically into every Dahua client ever shipped. The operator’s own code logs the result of probing this channel at scale: 89.4 percent of live serials returned an open, no-authentication channel. Nine out of ten cameras, reachable by anyone who could guess or harvest a serial number.

“The device never authenticates the connecting party. It authenticates the session, via a token the cloud issued before the device was contacted. Obtaining that token requires only the fixed SDK credentials shared by every legitimate Dahua application.” continues the report. “The only real barrier to reaching any camera through this path is knowing its serial number, precisely what the operator’s harvesting pipeline exists to produce at scale.”

Getting from the tunnel session to full admin access still requires valid credentials or an authentication bypass. However, the attacker’s own logs suggest that most exposed cameras did not need this final step.

There are also two important details about the reported CVEs. The tool links its persistent backdoor technique to CVE-2024-39943, but that CVE actually refers to a different command-injection flaw in Rejetto’s HTTP File Server. The technique is valid, but the CVE reference is wrong. Likewise, the relay abuse is not CVE-2025-31702, which Dahua describes as a narrower authenticated privilege-escalation flaw. Incorrect CVE references can send defenders looking for the wrong fix.

Hunt.io also found something that had nothing to do with cameras: a UPX-packed Windows binary, tagged as SalatStealer, staged on the same server alongside a PowerShell script that disables Windows Defender five different ways, including a Group Policy key built to survive reboots and Defender updates. The researchers treat it as a separate, unrelated capability riding along on shared infrastructure, not part of the camera campaign proper.

What stands out across the whole toolkit is that none of it was built from scratch. The brute-force engine, the bypass chain, the relay tooling, the recovery-code generator: each traces to a different public repository, credited (sometimes accurately) to at least six other developers. The operator assembled, patched, and rewrote, layering Russian comments over Spanish code in one component recovered in three separate stages of the same rewrite.

“The same toolkit also recovers stored device passwords outright, through a routine that derives its decryption key entirely from values the attacker already holds, device class prefix and serial number, so no device secret is needed. A residual Spanish comment in that code confirms it came from the same upstream source as the original brute-forcer.” states the report.a

The offline recovery-code generator is arguably the most consequential piece precisely because it doesn’t need a compromised device at all. Given a live serial number, it derives a code entirely offline that unlocks Dahua’s cloud-level account-recovery flow, no current credentials required. Removing a backdoor account doesn’t touch this. Only Dahua changing how the code is derived would.

For anyone running Dahua gear, or the OEM-rebranded lines built on the same backend (Amcrest, Lorex, Annke, Swann, among others), the practical checklist is short: check for a p2pwn account and remove it, disable P2P on any device where it isn’t actually needed, confirm firmware is patched against the 2021 bypass pair, and rotate every credential that camera ever held, since the exfiltration bot grabbed those too. None of that fixes the recovery-code problem. That one sits with the vendor.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

Project noRecognition: Teaching AI to Fool Surveillance Cameras

Researchers tested 31 million patterns to disrupt surveillance AI, with promising results but significant gaps between simulation and real-world use.

The Kansas City-based cybersecurity researcher Bill Swearingen spent the past year doing something that sounds almost too simple to work: printing patterns, watching cameras fail to detect them, and repeating. TechCrunch reports that after roughly 31 million tests, he can now generate patterns on demand that block license plate readers and surveillance cameras from recognizing whatever the pattern covers, whether that’s a person or a vehicle.

The project is called noRecognition, and the core idea isn’t stealth in the traditional sense. The camera still records everything just fine. What breaks is the detection layer sitting on top of the footage, the software that flags license plates, tracks faces, or spots “activity of interest” across thousands of hours of video. Swearingen’s patterns don’t hide you from the lens; they make the algorithm looking through that lens shrug and move on.

Swearingen, co-founder of the SecKC meetup, said his project started for personal reasons. He became concerned about the growing number of surveillance cameras in his town and the possibility of being tracked while attending a protest.

What started as a simple experiment later became a reinforcement learning system. He taught the model to create patterns, learn from failures and keep improving. Over time, it learned how to avoid detection by several camera systems.

Every time a pattern failed and got detected, the system adjusted and tried again, eventually learning to defeat multiple detection algorithms simultaneously rather than just one at a time.

The research dashboard behind the project, published at sandbox.norecognition.org, goes considerably deeper into the numbers than the headline claim suggests, and it’s refreshingly upfront about what’s proven versus what isn’t. The team states its overall objective plainly as “one pattern that defeats every detector,” and by their own account that goal remains only partially met. Their strongest validated result against a detector extracted directly from a real deployed surveillance camera sits at 61.7% non-detection across held-out test subjects, a solid number, but nowhere near total, and still a digital simulation rather than a real-world fabric test.

That distinction matters more than it might seem. Most of the dashboard’s headline figures are explicitly labeled as digital, simulated results, meaning the pattern was tested against a virtual camera and printed ink model rather than an actual garment photographed by an actual camera in the field. The gap between “works in simulation” and “works when Donut Media wraps a real 2009 Toyota Yaris in it,” which is the physical test Swearingen ran live at DEF CON, is exactly the gap this kind of research has to close before anyone should treat it as a reliable, everyday privacy tool.

“On Friday at the Def Con cybersecurity conference in Las Vegas, Swearingen ran his first real-world test. With help from Donut Media, the test involved covering a 2009 Toyota Yaris with one of Swearingen’s newest patterns to see if the car would be invisible to detection by a Flock camera.” reports TechCrunch.

“We proved it was effective,” said Swearingen, though the wheels were a challenge. The video of the demo will be out in the next few weeks, said Donut Media.”

That DEF CON demo is where things got concrete. Swearingen covered a car in one of his newest patterns and tested it against a Flock Safety camera, the kind widely deployed for automated license plate reading across the US. He said the test proved effective, though the vehicle’s wheels turned out to be a persistent weak point, curved surfaces apparently don’t cooperate with flat printed patterns the way a car door does.

Project noRecognition: Teaching AI to Fool Surveillance Cameras
Source Tech Crunch – A photo of a 2009 Toyota Yaris at the Def Con conference in Las Vegas, covered in a pattern made by Bill Swearingen, as part of a test to see if it can defeat surveillance camera detection.
Image Credits:Bill Swearingen / Donut Media

Swearingen is not publishing his best patterns because he does not want camera makers to easily find and block them. Instead, he is using crowdfunding to develop and sell printed products such as T-shirts and hoodies, with vehicle wraps possibly coming later.

It is still unclear whether the project will become a practical privacy tool for everyday users or remain mainly a DEF CON demonstration. Its real effectiveness will depend on how well the patterns work on real clothing, in different weather and camera conditions.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Surveillance camera)

Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage

Dutch intelligence says Russia hacks IP cameras to monitor NATO military logistics and weapons shipments to Ukraine.

The Netherlands’ AIVD and MIVD, the civilian and military intelligence services, published a joint advisory on July 10 confirming that at least one Russian intelligence service is systematically compromising internet-connected IP cameras across the Netherlands, other EU and NATO member states, and Ukraine to collect military intelligence.

The operation is ongoing. The advisory is based on intelligence gathered by both services and covers a campaign that has escalated since Russia’s full-scale invasion of Ukraine.

The immediate military application in Ukraine is the most direct part of the finding.

“The information obtained by the Russian state actor via digital espionage operations targeting IP cameras provides insight into relevant military data, such as EU and NATO military transport routes and weapon deliveries to Ukraine. The Russian state actor uses image recognition software to conduct targeted searches for military vehicles and the military cargo they are transporting. In some cases, the access to IP cameras gained by the Russian state actor in Ukraine is used to identify the locations of Ukrainian military personnel.” reads the advisory. “Intelligence reveals that this information is subsequently used to neutralise Ukrainian military personnel and military materiel in use by the Ukrainian armed forces. Furthermore, the Dutch services have determined that the Russian service is using the access to IP cameras to acquire relevant military intelligence in EU and NATO member states, including information that is not directly relevant to the war in Ukraine.”

A roadside camera or a business camera overlooking a loading area becomes a targeting asset. That’s the direct line from a default password left unchanged to a strike on Ukrainian forces.

The surveillance operation in EU and NATO member states serves a different but related purpose.

“Furthermore, the Dutch services have determined that the Russian service is using the access to IP cameras to acquire relevant military intelligence in EU and NATO member states, including information that is not directly relevant to the war in Ukraine.” confirms the advisory. “To date, the Dutch services have not observed the Russian state actor using such information for military attacks outside Ukraine.”

The intelligence collected includes EU and NATO military transport routes and weapons deliveries bound for Kyiv. The Dutch services separately confirmed they caught a small number of cameras breached directly on military logistics routes inside the Netherlands, and warned the organizations running them so they could act.

The services are explicit that this isn’t a one-off campaign.

“The Dutch services assess that there has been a systematic increase in the number of digital espionage operations by Russian state actors to support military operations since the start of the war in Ukraine. The digital activities that target IP cameras form only a small part of their operations.” continues the joint advisory. “The Russian authorities derive significant tactical and strategic advantages from the deployment of cyber operations, from both defensive and offensive perspectives. For example, the MIVD has previously issued a warning about exploratory activities by Russian state actors targeting logistical routes, including routes in the Netherlands”

The camera surveillance is described as a small part of a much larger digital intelligence effort.

Getting into a camera isn’t technically sophisticated. The operators scan for internet-connected devices, fingerprint cameras by brand, and walk into those still running default passwords, outdated firmware, or factory settings. Once they’re in, image-recognition software runs automated searches through the video feed looking for military vehicles and the cargo they carry. No zero-days required.

“Once an IP camera has been identified, the malicious actor can attempt to gain access to the IP camera via the internet. This is often a relatively simple process, since many IP cameras that are connected to the internet lack adequate security measures.” states the advisory. “For example, they often have default passwords, obsolete firmware and factory configurations.”

The Dutch services have not observed the same camera-derived intelligence being used for military attacks outside Ukraine. But they say this demonstrates that Russia has the capability to do so, and that the same approach could be applied by Russian military units in a future conflict. That’s not a hypothetical being raised for rhetorical effect. It’s an assessment of demonstrated capability.

The most important variables, according to the advisory, are what the camera can see and whether it’s reachable from the public internet. On the first: cameras should be positioned for their actual purpose and should avoid covering logistics routes, loading docks, ports, or any area where military movements or weapons shipments pass. Sensitive zones within the field of view should be masked or blurred where possible, and GPS location data should be stripped from video streams.

On accessibility: live streams should not be publicly reachable unless there’s an essential reason for it. Port forwarding and UPnP should be disabled. Remote access should go through a VPN rather than direct exposure. Default passwords should be changed immediately on installation, admin accounts should be kept separate from stream-viewing accounts, and MFA should be enabled wherever the device supports it. The advisory also flags the origin of the hardware itself: China, Russia, and Iran are cited as countries actively running offensive cyber programs targeting Dutch and European interests, and buyers should factor that into procurement decisions.

Cybersecurity firm Censys counted more than 87,000 internet-connected cameras across EU and NATO countries and Ukraine running services matching known-exploited vulnerabilities. In the Netherlands alone, more than 45,000 cameras are reachable from the public internet.

The numbers illustrate the scale of the exposed surface the advisory is addressing. Fixing it doesn’t require new technology. It requires treating a camera pointing at a transport route with the same security discipline as any other system connected to the internet.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, IP cameras)

MIT to Become Hotbed of AI Video Surveillance

It’s a lot:

According to information obtained by The Tech, MIT is spending over $3 million on more than 500 AI surveillance cameras in academic buildings, residence halls, and outdoor areas along Memorial Drive. Installation of the new cameras, along with the wiring and infrastructure that will support them, began November 2025 and will likely continue until September 2026.

Technical specifications for the cameras suggest that they will be capable of collecting real-time face and object classification data, including detection of motion, loitering, crowds, face masks, and camera tampering. Individuals can also be automatically classified on the basis of clothing color, gender, and age, up to a distance of 35 feet (11 meters) from the camera. According to a statement from MIT spokesperson Kimberly Allen, any collected data is “retained up to 30 days,” unless an exception is granted.

[…]

Most of the new cameras, which are part of Hanwha’s Wisenet AI line, are marketed for their ability to identify and classify multiple objects with deep learning algorithms. They support resolutions ranging from 2MP to 4K while also recognizing faces, license plates, vehicles, and other objects in real time.

Nearly all cameras will accommodate a wide range of pan, tilt, rotate, and zoom motion and will be monitored continually with Ai-RGUS, an AI camera software.

Yikes.

On Flock License Plate Tracking Cameras

A recent story of a writer who was mistakenly identified, tracked, and arrested using data from Flock cameras has gone viral.

The New Jersey plates that were allegedly stolen from the LA dealer were 34 03 DTM, not 34 10 DTM. But when the police report was created and the plate was entered into Flock’s system, it was just recorded as 34 DTM. Just the five large characters, no little number in the middle. And Flock’s AI tech wasn’t registering that non-standard little number when it began picking up the Range Rover around town. It just saw 34 DTM in large type and started alerting the local police.

As we all stood there shaking our heads, including my wife, who was finally allowed to join me, I connected the final dot. A lot of vehicles in JLR’s media fleet have a New Jersey manufacturer plate with the same alphanumeric structure­34 ## DTM­and Officer Ganshyn observed that meant it was now a nationwide issue. Anywhere a police department has a partnership with Flock, any other JLR-owned car with the same plate structure is going to get flagged as stolen. In fact, four other 34 ## DTM cars were being tracked around Minnesota that week, according to Officer Ganshyn. I was just the first one to get nabbed. The only way to stop it would be for the LAPD to correct their initial report and update Flock’s system, which Jaguar Land Rover was now racing to make happen following the phone call.

Flock has responded to the bad press. First, they affirmed that their systems were working correctly, and blamed the police:

The obvious question was that Flock cameras were looking for 34 DTM, and the plate on the car I was driving was 34 10 DTM. Why was that flagged as a match?

“The way that the ML [machine learning] works is it correctly read what it was supposed to read. It was fed those characters that you said, 34 DTM, and it spit back out [a result] with the characters, 34 DTM,” Thomas said. “It was asked, can you find this? And it did find that. It just didn’t say if there’s more here, then don’t do it. It just simply said, is it there? And the answer was yes.”

He explained that even if the 10 was normal size, Flock would still have flagged it as a match, because that’s how they’ve set it up according to law enforcement’s requests. Sometimes partial plates are all they have to go on at first.

“The way that law enforcement likes to use these tools is, if any of the characters that they have put into these hot lists get read, they want to get those alerts,” he said. “Now, what we try to train officers to do is to do what you said, which is to verify that 34 DTM is what I’m looking for, and what I’m seeing is 34 10 DTM.”

Second, Flock’s CEO has apologized for calling privacy advocates terrorists:

The CEO of Flock Safety, the company that runs an enormous network of cameras used by police departments across the U.S., hasn’t been shy about taking on Flock’s critics. Last year, he even called one group that tracks the location of Flock cameras “terrorists.” But he’s had a change of heart. Or, at the very least, a change in PR strategy.

Meanwhile, the police are using (alternate source) the Flock camera network to track people in addition to cars:

Police departments around the country have used Flock cameras at least hundreds of times to search for specific people, not cars, using searches such as “heavy-set male with a black and white hat,” “person on skateboard,” and “person wearing orange vest and construction hat,” according to data reviewed by 404 Media. Sometimes searches reference a target’s race or signs of their political affiliation.

And, like all police surveillance technologies, there are abuses.

A Video Screen That Is Also a Camera

Amazing:

Researchers from ETH Zurich in Switzerland, however, managed to create a new type of pixel that can simultaneously do both. This hypercharged pixel, called a Fourier pixel, can generate and sense arbitrary light fields and tap into a pixel’s full potential for carrying information by manipulating light’s intensity, oscillation phases, and polarization. The team reported its findings in a paper published yesterday in Nature.

We are one step closer to 1984 technology:

The telescreen received and transmitted simultaneously. Any sound that Winston made, above the level of a very low whisper, would be picked up by it; moreover, so long as he remained within the field of vision which the metal plaque commanded, he could be seen as well as heard. There was of course no way of knowing whether you were being watched at any given moment.

Paper.

Flock Cameras Can Surveil Cars Without License Plates

This is from a 2024 company presentation:

Officers can also tap into data showing a car’s decals, bumper stickers, back and top racks—along with temporary and unique state tags.

Flock calls it a “Vehicle Fingerprint” and it’s touted as a way for law enforcement officials to get more information “even when you don’t have full plate information,” the company’s presentation shows.

The company gives police officers the ability to search that data as well, to “build stronger cases with less information upfront.” That includes being able to locate multiple vehicles law enforcement officials believe are moving together and what Flock calls a “multi geo search.”

This kind of thing is older than AI; I wrote about it in my 2014 book Beyond Fear. Edward Snowden revealed that the NSA was using cell phone location data to track phones that were habitually near each other.

As bad as Flock is, remember that anyone with broad access to cell phone location data can do the same thing.

The Realities of AI Video Surveillance

The Financial Times has a good article on how AI is changing the capabilities of video surveillance, with information from both Israel/Iran and Russia.

I wrote about this sort of thing a few years ago, how AI enables mass spying in the way that computers and networks enabled mass surveillance. The interesting development in the article is that AI allows people to ask natural language questions about video footage to AIs—and AIs can answer them.

In contrast with older tools restricted to a few dozen preset searches, these new tools allow an almost unlimited range of enquiries by enabling language-based searches on video.

That lets intelligence officers hunt through massive streams of videos using simple search terms, such as two men handing a bag to each other; a person who has changed their appearance, or has changed clothes multiple times in a day; or a vehicle that has recently been painted over, or has driven past the same spot several times in a short period.

“This is the holy grail of surveillance,” said a European official whose country uses the technology on its cities. “We are able to look for behaviour, not objects ­ it has created a world of new possibilities.”

The Privacy Problem With Meta’s Ray-Ban Smart Glasses

This episode discusses Meta Ray-Ban Smart Glasses, which blend a camera, microphone, AI features, and social media integration into sunglasses that look like normal fashion eyewear, raising major privacy concerns. It highlights reports that footage captured by the glasses may be reviewed by human contractors to help train Meta’s AI systems, and notes critics’ concerns […]

The post The Privacy Problem With Meta’s Ray-Ban Smart Glasses appeared first on Shared Security Podcast.

The post The Privacy Problem With Meta’s Ray-Ban Smart Glasses appeared first on Security Boulevard.

💾

❌