Eagle Eye Networks

Devil’s Ivy Update

augusti 8, 2017 Eagle Eye Networks

devils-ivy-update-fi

In July 2017, cyber security researchers discovered a serious flaw, which they named “Devil’s Ivy”, that exists in nearly all cameras supporting the popular ONVIF specification. The flaw allows hackers to take full control of ONVIF-compliant cameras.

Most camera makes and models are vulnerable, including top brand high-quality cameras. Within days a few major manufacturers issued firmware updates that correct the flaw. It is up to camera owners and servicing contractors to update the cameras. There is no telling which manufacturers will make firmware corrections for their cameras, or how many of the millions of vulnerable installed cameras will actually be updated.

When vulnerable cameras and recorders can be contacted directly from the Internet, they can be easily attacked and exploited by cyber criminals and other attackers. Strong cyber security controls and constant vigilance are needed to avoid recorders being compromised. Any device connected to the Internet is typically attacked or probed hundreds of times per day, especially DVRs and NVRs, as they are a high-value target.

This is a clear example of why segmenting your network or utilizing technology like Eagle Eye Camera Cyber Lockdown is critical. Eagle Eye Camera Cyber Lockdown isolates the cameras from other networks so that they cannot be maliciously attacked nor utilized if they contain a trojan or other malware.

devils-ivy

Andra inlägg som kan intressera dig

loading

Log4j Security Update

On Friday, Dec. 10, 2021 the Apache Software Foundation disclosed a critical vulnerability (CVE-2021-44228) in its “Log4j” software. The disclosure has received extensive news coverage because of the ubiquity of…

december 13, 2021 Phillip Farr

The Dangers of Connecting Cameras Directly to the Internet

Dean Drako Dean Drako is the founder and CEO of Eagle Eye Networks, the global leader in cloud video security. Eagle Eye Networks ranked #133 in Deloitte’s 2019 Technology Fast…

mars 18, 2020 Eagle Eye Networks

Macy’s Hit in Cyber Data Breach

Macy's and Bloomingdales join a long list of retailers hit with cyber breaches this year, including Adidas, Under Armour, Forever21, Saks Fifth Avenue and Lord & Taylor. In a notice…

augusti 3, 2018 Eagle Eye Networks