A new project called IP Crawl has created a searchable map documenting thousands of unsecured webcams accessible directly from the public internet. The discovery highlights a widespread misconfiguration issue affecting consumer and commercial devices.
IP Crawl operates as a living atlas, continuously scanning for and cataloging webcams with default credentials or open ports. The project indexes devices across multiple regions, making it possible to locate and access feeds with minimal technical knowledge.
The exposed cameras span residential and commercial installations, from baby monitors to security systems. Most instances result from users failing to change default passwords or misconfiguring network settings during setup.
Security researchers note the discovery underscores persistent IoT device vulnerabilities. Manufacturers often ship products with weak security defaults, and users frequently neglect basic hardening steps. The public nature of IP Crawl's database has sparked discussion about responsible disclosure, with some arguing the project raises necessary awareness while others warn it facilitates unauthorized access.
Experts recommend users disable remote access unless necessary, change all default credentials immediately, and keep firmware updated. Network administrators should implement proper segmentation to isolate IoT devices from sensitive systems.
Dropbox is notifying users of unauthorized account access resulting from an email verification vulnerability in Lenovo's identity system. Attackers exploited the flaw to create fraudulent Lenovo IDs and gain entry to Dropbox accounts.
A California federal grand jury has indicted a Russian national for orchestrating a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware.
The FBI is investigating a newly launched dark web service called Nexus that claims to possess digital scans of over 153 million driver's licenses from US and Canadian residents. The service is actively selling the stolen identification data.
International law enforcement agencies and private sector partners have seized infrastructure belonging to the Sality malware botnet, a peer-to-peer network used for unauthorized computer access and data theft.