Somewhere in a SANS honeypot log this week, a scanner pinged a Hikvision Intelligent Security API for the umpteenth time this year. Not a new vulnerability. Not a fresh zero-day with a catchy name. Just the same old scan, hitting the same old device class, because it still works often enough to be worth automating. That’s the joke buried in this week’s news: while everyone’s attention was on a SonicWall zero-day exploited before anyone even had a patch to apply, the far more mundane threat was quietly grinding away in the background, the way it has for years.

That’s the uncomfortable truth about cybersecurity in 2026. The dramatic stuff, root-access zero-days, nation-state ClickFix campaigns, gets the writeups and the CVE numbers. But the boring stuff, a camera with a known bug from five product generations ago, still sitting on a public IP with default credentials, is what actually keeps a whole category of botnets alive. Nobody wrote an incident response plan for “we forgot the DVR was internet-facing.” They should have.

Why Are We Still Talking About Hikvision Cameras

Hikvision’s vulnerability history reads like a syllabus for internet-facing IoT: authentication bypasses, hardcoded credentials, command injection, the works. Researchers have been flagging issues for the better part of a decade. And yet the scanning never stops, because the install base never really shrinks. Cameras get bolted to a wall, plugged into a network, and forgotten. Nobody puts “rotate the DVR firmware” on a recurring calendar invite. Meanwhile the device sits there with a management interface reachable from the open internet, waiting for whichever botnet operator gets around to it next.

This is the part that doesn’t make headlines: mass scanning isn’t noise you can safely ignore. It’s reconnaissance. Every honeypot hit against a known Hikvision API path is an attacker (or more likely, an automated crawler working for one) checking whether your device is still exposed and still vulnerable. If it is, you’ve just been enrolled in something, and you probably won’t find out until the device is participating in a DDoS botnet or pivoting into the rest of your network.

SANS Internet Storm Center logo representing honeypot scan monitoring
Honeypot networks keep catching the same old scans against known-vulnerable camera APIs, year after year.

Zero-Days Get Headlines. Old CVEs Get Botnets.

Compare that to the SonicWall SMA situation. A threat actor tracked as UTA0533 was exploiting unpatched SMA 1000 series appliances for root access before the vulnerabilities were even publicly disclosed. That’s genuinely alarming, and it deserves the attention it’s getting. But it’s also rare. Zero-day exploitation before disclosure requires resources, research time, and a target valuable enough to justify burning an undisclosed bug. Most attackers don’t have that budget. What they have is a list of known CVEs against device classes that are cheap to scan for and slow to patch.

That asymmetry matters for how you allocate defensive effort. You can’t personally out-research a nation-state’s zero-day pipeline, and chasing every advisory the moment it drops is a losing game when six hundred patches land in a single Tuesday. What you can control is whether your organization has a camera, a VPN appliance, or a management interface sitting exposed with a five-year-old firmware version and a default password. That’s not a hypothetical risk. It’s an active one, right now, being scanned for by someone.

Even the human-targeted attacks fit the pattern. Russian state group UAC-0145 has been running ClickFix-style CAPTCHA lures against Ukrainian targets, tricking people into pasting malicious commands into their own Run dialog. It’s not sophisticated. It doesn’t need to be. Attackers keep reusing cheap, well-worn tricks because organizations keep leaving the cheap, well-worn openings unclosed. Sophistication is optional when the basics are still failing.

This Is What Cybersecurity Hygiene Actually Looks Like

Good cybersecurity practice isn’t glamorous. It’s an inventory spreadsheet nobody wants to maintain and a firewall rule review nobody wants to schedule. But it’s also the single highest-leverage thing most teams can do, because it closes off the exact attack paths that mass scanning depends on. Here’s the unglamorous checklist that actually moves the needle:

  • Inventory every internet-facing device, not just servers. Cameras, DVRs, printers, and building automation gear all count, and most asset inventories miss them entirely.
  • Pull management interfaces off the public internet. Put them behind a VPN or a jump host, full stop. Nothing that controls a camera or a firewall should be reachable by a random scanner.
  • Change default credentials at deployment time, not “eventually.” If it shipped with a default password, assume it’s already been logged somewhere.
  • Apply security hardening baselines to IoT and OT devices the same way you’d harden a server: disable unused services, close unused ports, and turn off UPnP unless something genuinely needs it.
  • Watch for brute-force activity and repeated auth failures on exposed services. Automated brute-force banning against SSH, RDP, and admin panels stops a huge share of opportunistic scanning before it turns into a foothold.
  • Build a patch cadence for embedded devices specifically, since firmware updates rarely happen automatically and someone has to own the process.

None of this replaces threat detection or incident response planning for the big stuff. Defense in depth means you still need logging, segmentation, and a plan for when something does get past the front door. But layering fancy threat detection on top of an exposed camera with factory credentials is like installing a smart lock on a door that’s propped open with a brick.

The Ongoing Work Nobody Wants To Own

The real problem isn’t that these vulnerabilities exist. It’s that nobody in most organizations owns the boring, recurring work of finding and closing them. Security teams are stretched thin chasing the urgent stuff, the zero-days, the active exploitation alerts, the vendor advisories with a two-week patch deadline. The unglamorous device sitting quietly on a segment nobody audits doesn’t generate a ticket until it’s already been compromised.

If you want one action item out of this, make it this: assign an actual owner to your exposed-device inventory, with a recurring review cadence, not a one-time cleanup project. Cybersecurity programs fail less often because of missing tools and more often because of missing ownership. The scan logs already tell you where the gaps are. Somebody just has to be the one who checks.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.