Spike in Attacks Targeting Digital Video Recorders in Ukraine
GreyNoise recorded a nine-day surge of CVE-2021-36260 exploitation attempts against Hikvision devices in Ukraine.
GreyNoise observed scanning and exploitation attempts against digital video recorders and Hikvision products in Ukraine from 21 September to 1 October 2026, after months of near-zero activity. Most attempts targeted CVE-2021-36260, an unauthenticated command-injection flaw, using a Hikvision IP camera/NVR remote command execution Nuclei template. Three PureVPN exit nodes in Lithuania (AS56630) and one Ukrainian address sent the same command test and installed nothing; GreyNoise attributes the VPN activity to one entity and rates the domestic IP as possibly related. The four IPs did not target sensors outside Ukraine, attempts from them stopped after 1 October, and GreyNoise did not connect the activity to concurrent Russian strikes.