Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine 65%

By Swati Khandelwal12%

7/20/2026, 12:13:00 PM

BS Summary: This article contains 26 faulty reasoning types, including Indoctrination, Confirmation Bias, and Anchoring Bias, with Ambiguity (Equivocation) as the most egregious example at 22.9% saturation with 191 hits. Analysis detected 1,412 faulty-reasoning hits from 835 analyzed words, generating a BS Score of 59.3% and a BS Rank of 65% (7,503 of 21,179 articles). This article is worse (more manipulative) than 64.60% of the article peer group.

At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. 
That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands' civilian and military intelligence services, which describe the operation as ongoing. 
In Ukraine, the surveillance has not stayed passive. 
Camera access there has been "used in attempts to neutralise Ukrainian military personnel" and destroy their equipment, the services say, turning an exposed roadside or business camera into a targeting aid. 
Across EU and NATO states, the services add, the same camera access is also collecting military intelligence that has nothing to do with the war. 
Getting in is rarely the hard part. 
The operators scan the internet for exposed devices, fingerprint IP cameras by brand, and walk into the ones still running default passwords, obsolete firmware, and factory settings nobody changed. 
From there, image-recognition software does the watching, running automated searches through the video for military vehicles and the cargo they carry. 
None of the access the advisory describes needs a zero-day. 
Just how exposed are these cameras? 
Being reachable from the internet is not the same as being hacked. 
"Having a camera publicly accessible doesn't make it hackable," writes Martijn Grooten, a principal security researcher at Censys, the internet-scanning firm, in the company's own analysis of the exposed surface. 
The surface, though, is enormous. 
Across the EU, NATO members, and Ukraine, Censys counted more than 87,000 internet-connected cameras running a service whose version matches a known-exploited vulnerability, a total it calls a lower bound. 
More than 4,000 of them sit in Ukraine. 
That total counts hosts running any vulnerable service, not cameras whose own software is broken, a caveat Censys raises itself. 
In the Netherlands, Censys found 45,386 cameras reachable from the public internet and flagged 1,992 as running a service with a known-exploited vulnerability. 
Narrow that to bugs in the camera software itself, and the figure drops to 541. 
Censys keeps the wider count on the logic that a foothold on one service can often be used to take over the whole host. 
Those version matches deserve their own caveat: a service banner is not a reachable exploit. 
Of the two bugs Censys highlights, CVE-2016-7407 sits in dropbearconvert, a local key-import tool in the Dropbear SSH server that runs code only when someone converts a malicious key file. 
It was fixed in July 2016, and Censys flagged 159 Dutch hosts for it. 
CVE-2021-39275 is an out-of-bounds write that Apache itself rates low, since no bundled module feeds untrusted data to the affected function, though a third-party one might. 
It was patched in Apache 2.4.49 in 2021, and 112 Dutch hosts run a matching version. 
Censys counts both as exploited in the wild, though neither sits in CISA's Known Exploited Vulnerabilities catalog. 
Set that exposed surface against confirmed intrusions. 
In a separate statement, the Dutch services said they had actually caught only a small number of cameras breached, sitting directly on military logistics routes inside the Netherlands, and that the organisations running them have since been warned so they could lock things down. 
The Hacker News has asked Censys whether its counts are version matches alone or confirm a vulnerable configuration, and what evidence classifies the two CVEs as exploited in the wild; we will update this story with any response. 
What defenders should do 
The recommended fixes are the dull, effective ones: 
Start by finding what is exposed: which cameras are reachable from the public internet through a forgotten port-forward, a UPnP mapping, or a vendor cloud relay. 
Prioritise the ones overlooking transport routes, ports, and other sensitive sites, and check their logs for access you do not recognise. 
Keep the video stream off the public internet: turn off port forwarding and UPnP, and reach cameras through a VPN. 
Replace default credentials and turn on MFA where the device supports it; where it does not, keep that camera off the public internet entirely. 
Aim the lens deliberately: keep logistics routes, loading docks, and other sensitive spots out of frame, and mask what you cannot avoid. 
Patch firmware and software, and when it is time to buy, choose cameras that ship with years of security support, not months. 
The services say they have not observed camera-derived intelligence being used for military attacks outside Ukraine. 
What makes the threat portable is how ordinary both halves are: the entry is often just a default login, and the value is set by where the camera happens to point. 
A compromised camera hands an adversary a live read on physical operations, when the trucks move, and who comes and goes, no deeper breach of the network required. 
The fix, then, is not just patching the device; it is taking it off the public internet and controlling what it can see. 
Article reasoning-pattern comparisonThis article: 11.1%Swati Khandelwal: 2.5%The Hacker News: 2.0%Confirmation Bias11.1%This article: 10.9%Swati Khandelwal: 1.5%The Hacker News: 1.2%Anchoring Bias10.9%This article: 6.0%Swati Khandelwal: 3.5%The Hacker News: 3.3%Availability Heuristic6.0%This article: 6.3%Swati Khandelwal: 1.4%The Hacker News: 1.4%Representativeness Heuristic6.3%This article: 0.0%Swati Khandelwal: 0.7%The Hacker News: 0.6%Hindsight Bias0.0%This article: 2.5%Swati Khandelwal: 2.4%The Hacker News: 2.5%Overconfidence Bias2.5%This article: 4.6%Swati Khandelwal: 2.9%The Hacker News: 2.8%Framing Effect4.6%This article: 1.8%Swati Khandelwal: 0.9%The Hacker News: 1.1%Loss Aversion1.8%This article: 1.0%Swati Khandelwal: 0.6%The Hacker News: 0.6%Status Quo Bias1.0%This article: 2.6%Swati Khandelwal: 0.1%The Hacker News: 0.1%Sunk Cost Effect2.6%This article: 5.3%Swati Khandelwal: 1.2%The Hacker News: 1.3%Optimism Bias5.3%This article: 0.0%Swati Khandelwal: 1.9%The Hacker News: 1.6%Pessimism Bias0.0%This article: 6.5%Swati Khandelwal: 6.5%The Hacker News: 6.8%Negativity Bias6.5%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 0.8%Self-Serving Bias0.0%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 0.4%Fundamental Attribution Error0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 3.0%Swati Khandelwal: 0.1%The Hacker News: 0.4%Out-Group Homogeneity Bias3.0%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 0.6%Halo Effect0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 1.9%Swati Khandelwal: 1.5%The Hacker News: 1.4%Recency Bias1.9%This article: 0.0%Swati Khandelwal: 0.2%The Hacker News: 0.2%Primacy Effect0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%Straw Man0.0%This article: 10.2%Swati Khandelwal: 4.0%The Hacker News: 4.0%Appeal to Authority10.2%This article: 7.2%Swati Khandelwal: 1.3%The Hacker News: 1.6%False Dilemma7.2%This article: 3.4%Swati Khandelwal: 0.7%The Hacker News: 0.5%Slippery Slope3.4%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Circular Reasoning0.0%This article: 10.4%Swati Khandelwal: 3.8%The Hacker News: 4.3%Hasty Generalization10.4%This article: 0.0%Swati Khandelwal: 0.2%The Hacker News: 0.1%Red Herring0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.2%Bandwagon0.0%This article: 5.1%Swati Khandelwal: 0.8%The Hacker News: 1.1%Appeal to Emotion5.1%This article: 1.0%Swati Khandelwal: 0.3%The Hacker News: 0.5%Begging the Question1.0%This article: 5.4%Swati Khandelwal: 2.0%The Hacker News: 1.9%Post Hoc (False Cause)5.4%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.0%Tu Quoque0.0%This article: 1.9%Swati Khandelwal: 0.7%The Hacker News: 0.6%Burden of Proof1.9%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Appeal to Nature0.0%This article: 0.0%Swati Khandelwal: 0.3%The Hacker News: 0.3%Composition/Division0.0%This article: 0.0%Swati Khandelwal: 1.1%The Hacker News: 1.0%Anecdotal0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%No True Scotsman0.0%This article: 22.9%Swati Khandelwal: 2.6%The Hacker News: 2.3%Ambiguity (Equivocation)22.9%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 3.1%Swati Khandelwal: 0.1%The Hacker News: 0.1%Special Pleading3.1%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 7.3%Swati Khandelwal: 1.1%The Hacker News: 1.4%Unattributed Quote7.3%This article: 0.0%Swati Khandelwal: 0.8%The Hacker News: 1.0%Quote-first Misdirection0.0%This article: 8.4%Swati Khandelwal: 2.7%The Hacker News: 2.3%Biased Writer Voice8.4%This article: 19.4%Swati Khandelwal: 5.1%The Hacker News: 4.5%Indoctrination19.4%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 2.9%Attempt to Sell a Product or S…0.0%

835 words analyzed.

Speakers

4speakers47%attributed speech445writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 15 words • 100.0% coverageWriter's voice • 35 words • 100.0% coverageAIVD and MIVD • 29 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageAIVD and MIVD • 31 words • 100.0% coverageAIVD and MIVD • 25 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 29 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageMartijn Grooten • 30 words • 100.0% coverageWriter's voice • 5 words • 100.0% coverageCensys • 30 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageCensys • 20 words • 0.0% coverageCensys • 23 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageCensys • 24 words • 0.0% coverageCensys • 15 words • 0.0% coverageCensys • 30 words • 0.0% coverageCensys • 14 words • 0.0% coverageApache • 26 words • 0.0% coverageCensys • 16 words • 0.0% coverageCensys • 17 words • 0.0% coverageWriter's voice • 7 words • 100.0% coverageAIVD and MIVD • 44 words • 0.0% coverageWriter's voice • 38 words • 0.0% coverageWriter's voice • 4 words • 100.0% coverageWriter's voice • 8 words • 100.0% coverageWriter's voice • 26 words • 100.0% coverageWriter's voice • 21 words • 100.0% coverageWriter's voice • 20 words • 100.0% coverageWriter's voice • 24 words • 100.0% coverageWriter's voice • 22 words • 100.0% coverageWriter's voice • 22 words • 100.0% coverageAIVD and MIVD • 16 words • 0.0% coverageWriter's voice • 31 words • 0.0% coverageWriter's voice • 28 words • 0.0% coverageWriter's voice • 23 words • 100.0% coverage
Selected voice

Martijn Grooten

100%flagged-word coverage
30 attributed words7.7% of attributed speech96% writer coverage
0%50.0%100.0%Unattributed Quote+100.0 ptsWriter: 0.0%Martijn Grooten: 100.0%100.0%Indoctrination-36.4 ptsWriter: 36.4%Martijn Grooten: 0.0%0.0%Biased Writer Voice-15.7 ptsWriter: 15.7%Martijn Grooten: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.