Who is responsible? You are!

July 2016 News & Events

Gone are the days of installing IP cameras without a care about security; and by that I mean information security or cyber security, or whatever you want to call it. A security company, Sucuri, was recently asked to help a small jewellery business suffering a distributed denial of service (DDOS) attack. The business’s website was receiving around 35 000 requests per second, which basically made the website useless for everyone.

Sucuri dealt with the attack, only to find the number of requests increasing to almost 50 000 after the site came back online. This is where the IoT (Internet of Things) comes into the picture. IoT devices have been used in attacks before, but this time the IoT devices were surveillance cameras that were connected to the Internet. To be more specific, Sucuri was able to identify over 25 000 IP addresses from cameras located around the world.

The cameras were located in 105 different countries. What is nice is that for once South Africa wasn’t in the top 10, although it was one of the 105.

The key issue here was the vulnerability the attackers took advantage of dates back to 2014. The software was developed in China and affects over 70 vendors who use it in their DVRs – which means the cameras attached to the DVRs can be compromised. You can read a technical investigation into the vulnerability at www.securitysa.com/*ksrce1, as well as a list of the affected vendors.

Fortunately, most of the vendors are small companies you probably haven’t heard of, but there are enough recognisable names to make one nervous. Of course, one doesn’t know who may have bought from these vendors and put their own branding on the product.

We also don’t know which vendors may have patched their products since the article was published, but we do know there are over 25 000 cameras out there that are still vulnerable. But these are only the ones discovered in this incident, how many more may be out there?

You can read the story at www.securitysa.com/*subot1, but the moral of the story is simply that you can not expect security when you are on the Internet for any reason. It would be nice if we could expect our vendors and service providers to do their jobs and ensure security, but at the end of the day it’s you who must take responsibility for your own kit.

This means buying trusted brands from suppliers and service providers who know what they are doing and won’t vanish into thin air after the account is paid. It also means taking responsibility for your own upgrades and security patches – even on cameras, NVRs and DVRs, as well as computers, laptops and servers. At the very least, include it in your SLA and check that it’s done.

This won’t solve all the malware and similar problems, but it will make it harder for malware deviants to ply their trade. Also, maybe it’s time for physical security vendors to upgrade their patch release schedules?

Andrew Seldon

Editor



Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

From the Editor's desk: Security goes mainstream
Technews Publishing News & Events
      Welcome to SMART Security’s SMART Mining & Industrial Security Handbook 2026. While the world is focused on cybersecurity and AI, physical security has become a board-level concern across South Africa’s ...

Read more...
Global security in 2026
Editor's Choice News & Events Security Services & Risk Management Industrial (Industry) Mining (Industry)
The World Security Report 2026 states: “In a world of increasing volatility, physical security has evolved. It is no longer just a defensive measure; it is a critical driver of corporate value.”

Read more...
Industry perspective on industrial cybersecurity
Technews Publishing News & Events Infrastructure Industrial (Industry)
The Industrial Security Harmonization Group has released a joint industry perspective highlighting a critical truth in industrial cybersecurity: secure communication is not determined by protocols alone, but by how they are deployed and managed in real-world environments.

Read more...
The control room problem that nobody wants to talk about
Technews Publishing Editor's Choice
WhatsApp has become the unofficial backbone of security communications across the mining and industrial sectors, but it was never designed to be a security tool.

Read more...
Controlling access for people and vehicles
IDEMIA STid Security Technews Publishing Editor's Choice Access Control & Identity Management Asset Management Industrial (Industry) Mining (Industry)
When it comes to access control, the security requirements of mines and the industrial sector are similar, requiring a layered approach that combines physical barriers, digital authentication, and continuous monitoring to protect personnel, assets, and operational continuity.

Read more...
Impro announces Primo update
News & Events Access Control & Identity Management Integrated Solutions
Impro Technologies recently held a launch event in which it introduced a series of new products, from new readers through to its updated Primo access management software.

Read more...
IQSight SmartSuite integration with XProtect
Surveillance News & Events AI & Data Analytics
Milestone Systems and IQSight have strengthened their collaboration with the release of SmartSuite, a consolidated plug-in suite for Milestone XProtect video management software, to cut installation time for system integrators by 70%.

Read more...
Claude Mythos wake-up call
Technews Publishing AI & Data Analytics Information Security
AI has crossed a critical cybersecurity threshold and frontier models are accelerating attack lifecycles and will enable attackers to identify and exploit vulnerabilities at scale and speed, through novel methods that were previously the domain of advanced nation-state entities.

Read more...
The future of smart living and connected security
Securex South Africa Smart Home Automation News & Events
From controlling access and surveillance remotely to managing energy use during blackouts, smart technologies are transforming how organisations and property owners operate, protect assets, and maintain uptime across residential and commercial environments.

Read more...
957 women killed in three months
News & Events Security Services & Risk Management
Despite years of summits, task teams and public commitments, South Africa’s femicide rate remains around five times higher than the global average, and too few are using the legal lifelines available.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.