At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands' civilian and military intelligence services, which describe the operation as ongoing. In Ukraine, the surveillance has not stayed passive. Camera access there has been "used in attempts to neutralise Ukrainian military personnel" and destroy their equipment, the services say, turning an exposed roadside or business camera into a targeting aid. Across EU and NATO states, the services add, the same camera access is also collecting military intelligence that has nothing to do with the war. Getting in is rarely the hard part. The operators scan the internet for exposed devices, fingerprint IP cameras by brand, and walk into the ones still running default passwords, obsolete firmware, and factory settings nobody changed. From there, image-recognition software does the watching, running automated searches through the video for military vehicles and the cargo they carry. None of the access the advisory describes needs a zero-day. Just how exposed are these cameras? Being reachable from the internet is not the same as being hacked. "Having a camera publicly accessible doesn't make it hackable," writes Martijn Grooten, a principal security researcher at Censys, the internet-scanning firm, in the company's own analysis of the exposed surface. The surface, though, is enormous. Across the EU, NATO members, and Ukraine, Censys counted more than 87,000 internet-connected cameras running a service whose version matches a known-exploited vulnerability, a total it calls a lower bound. More than 4,000 of them sit in Ukraine. That total counts hosts running any vulnerable service, not cameras whose own software is