- Joined
- Jan 22, 2026
- Messages
- 101
- Reaction score
- 948
Check Point has restored the chronology of the cyberattack and bombing.

Check Point researchers reported that since the beginning of the conflict, which began on February 28, several Iranian groups have been actively searching for vulnerable Internet-connected surveillance cameras in Israel and several countries in the Middle East. According to Sergey Shikevich, manager of the Threat Intelligence Group at Check Point Research, the company has recorded hundreds of attempts to exploit errors in IP cameras from two manufacturers, Hikvision and Dahua.
The list of countries targeted by the attacking infrastructure includes Israel, Qatar, Bahrain, Kuwait, UAE, Cyprus and Lebanon. Check Point connects the selected destinations with regions where there has been significant missile activity related to Iran recently. Analysts recalled that Iranian structures traditionally use cyber intelligence to prepare actions in the physical world, including access to cameras. Check Point cited an example from June 2025, when groups affiliated with Iran's Ministry of Intelligence and Security gained access to servers with live CCTV broadcasts from Jerusalem, followed a few days later by rocket attacks on the city.
In a recent report released on Wednesday, Check Point called the current wave of interest in cameras from "several actors associated with Iran" a possible early signal of preparation for follow-up actions in the physical plane. The company claims that the attacking infrastructure combined commercial VPN outlets (Mullvad, ProtonVPN, Surfshark, NordVPN) and rented VPS, and the scanning was aimed only at Hikvision and Dahua devices without attempts to interact with other brands.
Check Point lists a set of vulnerabilities around which exploitation attempts were built: authentication problems in the Hikvision firmware (CVE-2017-7921), command injection in the Hikvision web component (CVE-2021-36260), command injection in the Hikvision Intercom Broadcasting System (CVE-2023-6895), unauthorized remote code execution in Hikvision Integrated Security Management Platform (CVE-2025-34067), as well as authentication bypass in a number of Dahua products (CVE-2021-33044). Patches are already available for all listed defects.
Researchers noted similar attempts during the 12-day conflict between Israel and Iran in June 2025, when access to cameras could be used to assess the effects of strikes. As an example, Check Point points to the episode with the Weizmann Institute of Science, which was reportedly hit by a ballistic missile shortly after the street camera aimed at the building was compromised.
Check Point's recommendations mention updating firmware and software to current versions, avoiding direct camera access from the Internet, isolating devices on a dedicated VLAN without side access to corporate or technological networks, as well as monitoring repeated failed login attempts and suspicious remote logins. Shikevich noted that Check Point has not yet observed attacks on targets in the United States, but the company expects an expansion of activity in the coming days or weeks.
Against the background of the current conflict, the bulk of Iranian cyber activity, according to Check Point, is focused on Israel and the Persian Gulf countries and more often takes the form of disinformation, cyber espionage and DDoS attacks by numerous "hacktivist" groups. Individual government-linked teams have the potential for disruptive operations, but in such campaigns, participants often exaggerate the results for public effect.
An additional risk, according to Justin Moore, senior manager of Unit 42 at Palo Alto Networks, is the increased activity of pro-Russian "hacktivists" over the past week. Unit 42 believes that such a movement expands the attack surface in the region and increases the likelihood of using highly destructive techniques familiar from operations against the interests of NATO and European organizations.

Check Point researchers reported that since the beginning of the conflict, which began on February 28, several Iranian groups have been actively searching for vulnerable Internet-connected surveillance cameras in Israel and several countries in the Middle East. According to Sergey Shikevich, manager of the Threat Intelligence Group at Check Point Research, the company has recorded hundreds of attempts to exploit errors in IP cameras from two manufacturers, Hikvision and Dahua.
The list of countries targeted by the attacking infrastructure includes Israel, Qatar, Bahrain, Kuwait, UAE, Cyprus and Lebanon. Check Point connects the selected destinations with regions where there has been significant missile activity related to Iran recently. Analysts recalled that Iranian structures traditionally use cyber intelligence to prepare actions in the physical world, including access to cameras. Check Point cited an example from June 2025, when groups affiliated with Iran's Ministry of Intelligence and Security gained access to servers with live CCTV broadcasts from Jerusalem, followed a few days later by rocket attacks on the city.
In a recent report released on Wednesday, Check Point called the current wave of interest in cameras from "several actors associated with Iran" a possible early signal of preparation for follow-up actions in the physical plane. The company claims that the attacking infrastructure combined commercial VPN outlets (Mullvad, ProtonVPN, Surfshark, NordVPN) and rented VPS, and the scanning was aimed only at Hikvision and Dahua devices without attempts to interact with other brands.
Check Point lists a set of vulnerabilities around which exploitation attempts were built: authentication problems in the Hikvision firmware (CVE-2017-7921), command injection in the Hikvision web component (CVE-2021-36260), command injection in the Hikvision Intercom Broadcasting System (CVE-2023-6895), unauthorized remote code execution in Hikvision Integrated Security Management Platform (CVE-2025-34067), as well as authentication bypass in a number of Dahua products (CVE-2021-33044). Patches are already available for all listed defects.
Researchers noted similar attempts during the 12-day conflict between Israel and Iran in June 2025, when access to cameras could be used to assess the effects of strikes. As an example, Check Point points to the episode with the Weizmann Institute of Science, which was reportedly hit by a ballistic missile shortly after the street camera aimed at the building was compromised.
Check Point's recommendations mention updating firmware and software to current versions, avoiding direct camera access from the Internet, isolating devices on a dedicated VLAN without side access to corporate or technological networks, as well as monitoring repeated failed login attempts and suspicious remote logins. Shikevich noted that Check Point has not yet observed attacks on targets in the United States, but the company expects an expansion of activity in the coming days or weeks.
Against the background of the current conflict, the bulk of Iranian cyber activity, according to Check Point, is focused on Israel and the Persian Gulf countries and more often takes the form of disinformation, cyber espionage and DDoS attacks by numerous "hacktivist" groups. Individual government-linked teams have the potential for disruptive operations, but in such campaigns, participants often exaggerate the results for public effect.
An additional risk, according to Justin Moore, senior manager of Unit 42 at Palo Alto Networks, is the increased activity of pro-Russian "hacktivists" over the past week. Unit 42 believes that such a movement expands the attack surface in the region and increases the likelihood of using highly destructive techniques familiar from operations against the interests of NATO and European organizations.