Back to The Local Vocal
The Local VocalHigh
Email
High risk 3rd Party Advisory 26 August 2026
RegionNew Zealand

Lock down your Dahua kit now

Attackers are actively compromising Dahua cameras and recorders using weak credentials, authentication bypasses, and relay access, so you should urgently review any exposed Dahua gear in your environment.

This is not an email campaign. It is an active compromise campaign targeting Dahua cameras and recorders that are reachable from the internet. If your business uses Dahua CCTV, NVRs, or related remote viewing features, you could be exposed without anyone needing to trick your staff first.

What gives it away is how direct the intrusion is. Researchers observed attackers getting in through credential attacks, authentication bypass weaknesses, and peer-to-peer relay access. In plain terms, that means some devices were accessed by guessing or reusing passwords, while others were reached through flaws that let attackers skip normal login checks or connect through remote access features that organisations often leave enabled.

The attacker is after control of the device and whatever it can provide next. If they get in, they can view or tamper with camera feeds, change settings, create persistence, and use the device as a foothold for wider network access. That can turn a physical security system into an entry point for surveillance, disruption, or follow-on compromise inside your business.

This is likely being seen widely because the campaign was reconstructed from an exposed attacker working directory and it targeted internet-accessible Dahua systems over several weeks. If your devices are externally reachable, use default or reused passwords, or rely on vendor relay features for remote access, you are in the same pool of likely targets.

Source: The Hacker News — https://thehackernews.com/2026/08/hackers-compromised-14500-dahua-devices.html

Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Check: Review whether your organisation uses Dahua cameras, NVRs, DVRs, or related remote access services anywhere in your environment.
  • Check: Confirm firmware is current, disable unnecessary peer-to-peer or relay access, restrict internet exposure, and reset any default, weak, or reused passwords on Dahua devices.
  • Do not: Ignore vendor or agency advisories. Acting within the recommended timeframe reduces exposure significantly.
  • Report: If the described threat or vulnerability is present, contact your IT provider immediately, and report to NCSC NZ at report.ncsc.govt.nz if active exploitation is suspected.
  • Contact Decision1: If you believe your business has been targeted, contact the Decision1 team immediately.