https://www.fortinet.com/blog/threat-research/mirai-based-bo...
However, going after just a brand solves nothing; the problem is that nobody can properly audit these devices due to their closed nature. A huge number of IP cameras and DVR/NVR devices have been either compromised for botnet installation or caught phoning home (usually somewhere in China) in the past. Unless one can purchase a fully Open Source one (including hardware and firmware), there are no guarantees that a device won't be doing nasty things, or silently waiting for remote triggers to do so, which is something that only source code inspection could guarantee against. In the meantime the solution has always been to put them behind a firewall that doesn't let them initiate connections to the outside and also filters out incoming connections from untrusted parties; this should apply to all closed connected device, not just Hikvision cameras.
https://www.wsj.com/articles/hackers-infect-army-of-cameras-...