Russian Spy Cameras, WordPress RCE, and AI Phishing Kits: Your Weekly Threat Brief
Three stories this week. All confirmed. All actionable. I will not dress them up.
The threat data from the past 24 hours points in a consistent direction: attackers are moving faster than most small businesses patch, and the tools being used against them are getting cheaper and more convincing by the month. Let us work through what actually matters.
Story One: Russian Intelligence Is Watching Through Your Camera
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine. The objective, according to reporting from The Hacker News citing Censys data, is surveillance of military transport routes, weapons shipments, and logistics infrastructure across NATO member states.
Censys identified 87,000 devices matching the profile of known-exploited camera services exposed to the internet across Europe.
Here is why this matters to a business in Birmingham or Bristol that has nothing to do with military logistics.
The cameras being exploited are not specialist military hardware. They are the same consumer-grade and SMB-grade IP cameras that sit above the reception desk, cover the warehouse loading bay, or monitor the car park. The attack vector is not sophisticated: default credentials that were never changed, or firmware that has not been updated since installation.
The intelligence objective may be military. The method is indiscriminate. Any exposed, unpatched camera with default credentials is a candidate.
What the data actually shows: The exploits being used include CVE-2021-39275 and CVE-2016-7407. That second CVE is from 2016. A decade-old vulnerability. Still working. Still being used by a state intelligence service in 2026, because enough cameras have never been patched.
This is not scaremongering. This is a documented, confirmed campaign using old vulnerabilities on neglected hardware.
Story Two: WordPress Has a Pre-Authentication Remote Code Execution Vulnerability
CVE-2026-63030, publicly named WP2Shell, allows an unauthenticated attacker to execute arbitrary code on the web server running a WordPress installation. No login required. No credentials needed. Send a crafted request, run code.
WordPress powers more than 41% of all websites on the internet, according to W3Techs. Estimates suggest over half a billion sites run it. The attack surface is enormous.
The German federal government’s cybersecurity agency rated this vulnerability at their second-highest severity level, indicating an expectation of significant disruption to businesses. The Dutch NCSC has also issued an urgent patching advisory for related Microsoft SharePoint vulnerabilities in the same window, reflecting a broader pattern of critical web infrastructure flaws being actively exploited this week.
The specific risk for UK small businesses: Many SMBs run their own WordPress sites, either directly or through an MSP or web agency. If the person responsible for that site does not have automatic updates enabled, or if the site is on a managed hosting plan where updates are batched, there is a window of exposure. Proof-of-concept code for WP2Shell was made public before patches were widely deployed. That gap is when exploitation accelerates.
Searchlight Cyber, the firm that identified WP2Shell, initially withheld technical details given the severity. Those details are now in circulation.
Story Three: What an AI Phishing Toolkit Actually Looks Like
Rapid7 researchers found an attacker’s delivery server left wide open. They pulled 1,048 files. What those files contained is instructive.
The toolkit included LLM-generated phishing lure templates, filename-spoofing tests, execution experiments, WebDAV-based malware droppers, and builder tools. This is not a hobbyist operation. This is an industrialised phishing pipeline using large language models to generate convincing, localised, grammatically correct lures at scale.
The campaign was targeting victims via WebDAV links, a file-sharing protocol that Windows handles natively. A user clicks a link, Windows mounts a remote file share automatically, and the malicious payload executes. The technique exploits legitimate Windows behaviour, which means many endpoint tools do not flag it.
The CVEs associated with this campaign include CVE-2025-33053 and CVE-2025-24054, both relating to Windows handling of WebDAV and SMB connections.
What this means in practice: The phishing emails your staff receive in 2026 are not the badly spelled, obviously suspicious messages of five years ago. They are LLM-polished, contextually appropriate, and designed to pass a casual read. The old advice, “check for spelling mistakes,” is no longer sufficient protective guidance.
Why This Gives UK SMBs an Edge, If They Act
Large organisations move slowly. Policy committees, change management boards, procurement cycles. A 20-person business can change its camera credentials this afternoon. It can enable WordPress auto-updates before lunch. It can brief staff on WebDAV links in a ten-minute all-hands.
Speed of response is a genuine competitive advantage for smaller organisations. The window between a vulnerability being confirmed and being exploited at scale is narrowing. Businesses that patch in hours rather than weeks survive incidents that others do not.
Clients and procurement teams increasingly ask about security posture. Being able to demonstrate that your business responds to confirmed threats within 24 hours is a differentiator. It is also the kind of evidence that reduces your cyber insurance premium over time.
Making the Case to Your Decision-Maker
If you need budget or sign-off to act on any of the above, three arguments worth making:
The camera issue is a GDPR exposure. If a compromised camera captures images of staff, customers, or visitors, and that footage is being streamed to a hostile foreign intelligence service, that is a personal data breach under UK GDPR. The ICO does not make exceptions for state-sponsored attackers. The obligation to secure personal data falls on the data controller, which is your business.
The WordPress vulnerability has proof-of-concept code in the wild. This is not theoretical. The German government’s second-highest alert rating reflects an assessment that exploitation at scale is expected. A compromised website is a reputational and operational incident, not just a technical problem.
The AI phishing toolkit lowers the cost of attacking you. The barrier to running a convincing phishing campaign has dropped significantly. Attackers who previously lacked the language skills or template design capability to target UK businesses convincingly can now generate polished, contextually appropriate lures using freely available tools. The volume of credible phishing attempts targeting UK SMBs will increase. Staff awareness needs to keep pace.
What to Do Before the End of This Week
1. Audit every IP camera on your network today. Log into each one. Change the default administrator password to something unique, generated by a password manager. Check when the firmware was last updated and apply any available updates. If you cannot log in because you do not know the credentials, that camera needs to be factory reset and reconfigured before it touches your network again.
2. Update WordPress core and all plugins immediately. Log into every WordPress admin panel you are responsible for. If you use managed hosting, contact your provider today and confirm that CVE-2026-63030 has been patched. Do not accept “we handle updates automatically” as sufficient. Ask for confirmation that this specific vulnerability has been addressed.
3. Disable or restrict WebDAV on Windows endpoints where it is not needed. This is a configuration change your IT provider or MSP can make. If staff do not need to mount remote file shares via web links, the attack surface used in the Rapid7-documented campaign is significantly reduced.
4. Update your phishing awareness guidance to staff. The specific message: any email containing a link that results in Windows asking for network credentials, or that opens a file share, should be treated as suspicious and reported immediately. The old heuristics no longer apply.
5. Check your Cyber Essentials scope includes IoT devices. Many CE assessments focus on desktops, laptops, and servers, and exclude IP cameras, smart TVs, and other networked devices. If your certification scope has gaps, your assessor needs to know. An unpatched camera with default credentials sitting on the same network as your business systems is a CE failure waiting to happen.
Before you go: follow the show wherever you listen, leave a rating or review, drop a comment with your thoughts, and share this with someone who would find it useful. If you run a small business and you found this brief useful, there is someone in your network who needs to hear it too.