#FactCheck: Old Jerusalem Clash Video Falsely Shared as Chaos at Tel Aviv Airport
Executive Summary
A video is being widely shared on social media showing a group of people clashing near a counter. The clip is being claimed to be from Ben Gurion Airport in Tel Aviv, Israel. Users allege that panic caused by Iranian missile threats has led people to try to flee the country, resulting in chaos and fights over flight tickets. However, a research by the CyberPeace found the claim to be false. Our findings reveal that the video is not related to the recent tensions and is actually from 2025.
Claim:
The viral video is being shared with the claim that chaos has erupted at Tel Aviv’s airport, with people trying to leave Israel due to Iranian attacks. An X user named “AjjuShane Experience (@AjjuShane)” shared the video with the caption: “We need tickets, we need flights, we want to leave Israel. We will not stay here until Iranian missiles crush us. Clashes are now happening at Tel Aviv’s Ben Gurion Airport.”
Post link:
- https://x.com/AjjuShane/status/2032584953112965238
- https://x.com/AjjuShane/status/2032584953112965238

Fact Check:
To verify the claim, we extracted keyframes from the video and conducted a reverse image search on Google. During the research , we found the same video on a Facebook page named Ynet, where it was shared on July 20, 2025.
- https://www.facebook.com/share/p/1NgTmpaZCs/
- https://www.facebook.com/share/p/1NgTmpaZCs/

The video carried a caption in Hebrew. Upon translation, it stated that the incident took place at “Cinema City” in Jerusalem, where dozens of Jewish youths clashed with Arab cafeteria workers. The visuals showed youths vandalizing property and throwing objects at staff members, while staff retaliated. Some individuals sustained minor injuries, but no serious harm was reported. We also found the same video on the YouTube channel of The Times of India, published on July 20, 2025. The caption mentioned that anti-Arab riots broke out inside a Cinema City theatre in Jerusalem on July 19, showing youths vandalizing the premises and clashing with Arab employees.

Conclusion:
Our research clearly shows that the viral video is from 2025 and unrelated to any recent Iran-Israel tensions. It is being misleadingly shared as a recent incident from Tel Aviv airport.
Related Blogs

Introduction
Not every major breach begins with a sophisticated new exploit. Sometimes it begins with a device nobody remembered to update, and this one began exactly that way, at scale. Security researchers have disclosed a campaign that compromised more than 14,530 internet connected cameras made by Dahua Technology, (one of the world's largest surveillance equipment manufacturers), using a mix of stolen credentials, two long known authentication flaws, and a peer to peer relay technique that let attackers reach devices tucked behind home and office routers. The operation, tracked by researchers at Hunt.io, has been named Operation CameraSwarm. It ran between June 17 and July 22, 2026, and was reconstructed almost entirely from an exposed 407 megabyte working directory the attackers themselves left accessible, containing over 2,600 files, campaign logs, shell history, and tooling. Confirmed compromises were concentrated in Ukraine and Russia, and researchers described the operators/attackers as Russian speaking based on language artifacts found in the recovered material, suggesting the campaign was most plausibly built around surveillance or access relevant to the ongoing conflict between the two countries, though no formal attribution to a named threat actor or state entity has been established or claimed. What makes this worth understanding in detail is not just the scale, though 14,500 compromised cameras is a serious number, but how mundane the actual break in methods were. None of this depended on the attackers discovering some brand new, unknown flaw, the kind of vulnerability security researchers call a ‘zero day’. It depended on something far more ordinary: thousands of devices running years-old software that had never been patched, combined with cheap automated tools that could try weak passwords and known exploits at scale.
What is Dahua, and why does this matter
Dahua Technology, founded in Hangzhou in 2001, is a publicly traded, partially state owned Chinese company and the world's second largest video surveillance manufacturer by revenue, trailing only fellow Chinese firm Hikvision. Its cameras, digital video recorders, and network video recorders are sold in roughly 180 countries through more than 2,100 partners, and the company has shipped tens of millions of devices into homes, retail stores, offices, and public infrastructure worldwide. That scale is precisely what makes any systemic vulnerability in Dahua's product line consequential well beyond a single country or sector.
How the attackers actually got in
Hunt.io attributed the compromises to three distinct attack paths. The largest, by far, was straightforward credential attacks, essentially automated login guessing using weak, default, or previously leaked passwords, which researchers traced to 12,324 unique IP addresses across more than 13,000 recorded campaign attempts. The second path exploited two authentication bypass flaws, catalogued as CVE-2021-33044 and CVE-2021-33045, both rated a severe 9.8 out of 10 on the current CVSS severity scale used by the US National Vulnerability Database. These are not new vulnerabilities. They were publicly disclosed back in 2021, and Dahua issued fixed firmware for them years ago, yet both remain listed today on the US Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog, a designation reserved specifically for flaws still being actively exploited in the wild despite available patches. The third and most technically interesting path involved a peer to peer, or P2P, relay mechanism built into Dahua's own Easy4IP cloud infrastructure, a system designed to let users remotely access their camera without manually configuring network settings. Security firm ITRES Labs, which documented this exposure separately in 2025, found that on firmware released before mid-2024, simply knowing a device's serial number was enough to establish a connection route through Dahua's relay servers before the camera's own login check ever kicked in, a design gap that let attackers reach devices even when they sat behind network address translation, the technical barrier that normally shields home devices from direct internet exposure. Hunt.io's recovered operator logs claimed an extraordinary 89.4 percent of live serial numbers tested returned an open channel without any authentication at all, though it is worth noting that figure comes solely from the attackers' own recovered data and has not been independently verified by Dahua, ITRES Labs, or any public incident response body as of this writing. Beyond the initial break in, the campaign also planted 1,923 cameras with a persistent account, essentially a backdoor login the operators could return to later, and researchers found evidence suggesting parts of the toolkit may have been built specifically to hand off access to a third party, though no confirmed link to a named threat actor or state sponsor has been established.
Why cameras remain such a persistent target
Internet connected cameras occupy an unusual position in the broader device ecosystem. Unlike a laptop or phone, they are rarely patched by an end user paying regular attention, they are often installed once and forgotten, and many owners never change the default credentials shipped from the factory. A compromised camera also offers an attacker something more than a foothold, live or recorded video feeds of homes, businesses, and sometimes sensitive facilities, which carries value well beyond the kind of access a compromised laptop typically provides.
CyberPeace Advisory | What device owners should do now
For anyone running Dahua surveillance equipment, or any internet connected camera system, several concrete steps meaningfully reduce exposure.
For Dahua device owners specifically:
Two steps address the exact mechanisms this campaign exploited.
- First, check the device's firmware version against Dahua's official download portal and apply the latest available update immediately, since the fixes for both 2021 authentication bypass vulnerabilities have existed for years and simply have not been applied on thousands of devices.
- Second, disable the P2P or Easy4IP remote access feature entirely unless it is actively required, since this is the exact mechanism the third attack path, the serial number based relay, relied on to reach cameras without any login check at all.
For any internet connected camera system, including in India:
The remaining precautions apply regardless of manufacturer, and are worth following on any brand of camera, DVR, or NVR connected to the internet.
- Replace default or weak passwords with strong, unique credentials on every camera and recorder, and remove any unused or unrecognised accounts, since the persistent account technique this campaign used depends entirely on unnoticed access surviving unchecked.
- Place surveillance devices on a segmented network separate from computers and phones, so that a compromised camera cannot become a stepping stone into more sensitive systems.
- Periodically audit which devices on a home or office network are internet facing at all, since many cameras end up exposed simply because remote access was left switched on by default and nobody thought to check.
- And where a device offers the option, disable any built in peer to peer or cloud relay convenience feature unless genuinely needed, since the underlying design pattern this campaign exploited, a remote access shortcut that runs before proper authentication.Is not unique to Dahua and has shown up across other camera brands in the past.
The view from India
This disclosure lands at a particularly relevant moment for India, which enforced sweeping new restrictions on Chinese origin CCTV equipment earlier this year. Since April 1, 2026, internet connected surveillance cameras sold in India have been required to carry Standardisation Testing and Quality Certification under Essential Requirements norms first introduced by the Ministry of Electronics and Information Technology in April 2024, It's a country-of-origin requirement under the Essential Requirements norms (introduced by India's Ministry of Electronics and Information Technology in April 2024), manufacturers must disclose the origin of key components like the System-on-Chip (SoC), and devices using Chinese-origin chipsets are reportedly not being granted approval by certifying authorities. Since Dahua's cameras, like Hikvision's and TP-Link's, generally rely on Chinese-made chipsets, the practical effect is that their products haven't received STQC certification, which functions as a blanket exclusion without the government needing to name any single company in the rule text itself. The stated rationale for that policy, concerns over hidden backdoor access, transmission of data to foreign servers, and deployment near sensitive locations, reads almost like a preview of exactly the kind of exposure Operation CameraSwarm has now documented in the wild. It is worth being precise here: the restriction applies to new sales, not existing installations, and CameraSwarm's confirmed victims were concentrated in Ukraine and Russia rather than India. But the underlying lesson travels well beyond any one country's borders. A camera manufactured with a convenience feature that bypasses its own login check, sitting unpatched for years despite a fix being publicly available, is a vulnerability that does not respect national boundaries, and India's decision to tighten certification requirements before an incident of this scale surfaced looks, in hindsight, considerably more prudent than reactive.
References
- The Hacker News, "Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P." August 19, 2026. https://thehackernews.com/2026/08/hackers-compromised-14500-dahua-devices.html
- Hunt.io, "Operation CameraSwarm: Dahua Cameras Compromised." https://hunt.io/blog/operation-cameraswarm-dahua-cameras-compromised
- ITRES Labs, "Dahua Beyond CVE-2025-31702: P2P Relay Exposure." October 29, 2025. https://labs.itresit.es/2025/10/29/dahua-beyond-cve-2025-31702-p2p-relay-exposure?
- Dahua Security, "DHCC-SA-202106-001: Security Advisory - Identity Authentication Bypass Vulnerability Found in Some Dahua Products." https://www.dahuasecurity.com/about-dahua/trust-center/dahua-psirt/dhcc-sa-202106-001%3Asecurity-advisory---identity-authentication-bypass-vulnerability-found-in-some-dahua-products
- National Vulnerability Database, "CVE-2021-33044 Detail." https://nvd.nist.gov/vuln/detail/CVE-2021-33044
- CISA, "Known Exploited Vulnerabilities Catalog." https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- Business Standard, "India to ban Chinese CCTV from Apr 1 as security concerns reshape market." https://www.business-standard.com/industry/news/india-ban-chinese-cctv-government-security-concerns-hikvision-dahua-market-126033000316_1.html
- PTC News, "India CCTV ban 2026: Hikvision, Dahua face STQC block as new security rules begin." https://www.ptcnews.tv/amp/nation/india-cctv-ban-hikvision-dahua-stqc-rules-2026-4422961
- Uyghur Human Rights Project, "Surveillance Tech Series: Dahua's Links to Human Rights Abuses in East Turkistan." https://uhrp.org/report/dahuas-links-to-human-rights-abuses-in-east-turkistan/
.png)
Introduction
The fast-paced development of technology and the wider use of social media platforms have led to the rapid dissemination of misinformation with characteristics such as diffusion, fast propagation speed, wide influence, and deep impact through these platforms. Social Media Algorithms and their decisions are often perceived as a black box introduction that makes it impossible for users to understand and recognise how the decision-making process works.
Social media algorithms may unintentionally promote false narratives that garner more interactions, further reinforcing the misinformation cycle and making it harder to control its spread within vast, interconnected networks. Algorithms judge the content based on the metrics, which is user engagement. It is the prerequisite for algorithms to serve you the best. Hence, algorithms or search engines enlist relevant items you are more likely to enjoy. This process, initially, was created to cut the clutter and provide you with the best information. However, sometimes it results in unknowingly widespread misinformation due to the viral nature of information and user interactions.
Analysing the Algorithmic Architecture of Misinformation
Social media algorithms, designed to maximize user engagement, can inadvertently promote misinformation due to their tendency to trigger strong emotions, creating echo chambers and filter bubbles. These algorithms prioritize content based on user behaviour, leading to the promotion of emotionally charged misinformation. Additionally, the algorithms prioritize content that has the potential to go viral, which can lead to the spread of false or misleading content faster than corrections or factual content.
Additionally, popular content is amplified by platforms, which spreads it faster by presenting it to more users. Limited fact-checking efforts are particularly difficult since, by the time they are reported or corrected, erroneous claims may have gained widespread acceptance due to delayed responses. Social media algorithms find it difficult to distinguish between real people and organized networks of troll farms or bots that propagate false information. This creates a vicious loop where users are constantly exposed to inaccurate or misleading material, which strengthens their convictions and disseminates erroneous information through networks.
Though algorithms, primarily, aim to enhance user engagement by curating content that aligns with the user's previous behaviour and preferences. Sometimes this process leads to "echo chambers," where individuals are exposed mainly to information that reaffirms their beliefs which existed prior, effectively silencing dissenting voices and opposing viewpoints. This curated experience reduces exposure to diverse opinions and amplifies biased and polarising content, making it arduous for users to discern credible information from misinformation. Algorithms feed into a feedback loop that continuously gathers data from users' activities across digital platforms, including websites, social media, and apps. This data is analysed to optimise user experiences, making platforms more attractive. While this process drives innovation and improves user satisfaction from a business standpoint, it also poses a danger in the context of misinformation. The repetitive reinforcement of user preferences leads to the entrenchment of false beliefs, as users are less likely to encounter fact-checks or corrective information.
Moreover, social networks and their sheer size and complexity today exacerbate the issue. With billions of users participating in online spaces, misinformation spreads rapidly, and attempting to contain it—such as by inspecting messages or URLs for false information—can be computationally challenging and inefficient. The extensive amount of content that is shared daily means that misinformation can be propagated far quicker than it can get fact-checked or debunked.
Understanding how algorithms influence user behaviour is important to tackling misinformation. The personalisation of content, feedback loops, the complexity of network structures, and the role of superspreaders all work together to create a challenging environment where misinformation thrives. Hence, highlighting the importance of countering misinformation through robust measures.
The Role of Regulations in Curbing Algorithmic Misinformation
The EU's Digital Services Act (DSA) applicable in the EU is one of the regulations that aims to increase the responsibilities of tech companies and ensure that their algorithms do not promote harmful content. These regulatory frameworks play an important role they can be used to establish mechanisms for users to appeal against the algorithmic decisions and ensure that these systems do not disproportionately suppress legitimate voices. Independent oversight and periodic audits can ensure that algorithms are not biased or used maliciously. Self-regulation and Platform regulation are the first steps that can be taken to regulate misinformation. By fostering a more transparent and accountable ecosystem, regulations help mitigate the negative effects of algorithmic misinformation, thereby protecting the integrity of information that is shared online. In the Indian context, the Intermediary Guidelines, 2023, Rule 3(1)(b)(v) explicitly prohibits the dissemination of misinformation on digital platforms. The ‘Intermediaries’ are obliged to ensure reasonable efforts to prevent users from hosting, displaying, uploading, modifying, publishing, transmitting, storing, updating, or sharing any information related to the 11 listed user harms or prohibited content. This rule aims to ensure platforms identify and swiftly remove misinformation, and false or misleading content.
Cyberpeace Outlook
Understanding how algorithms prioritise content will enable users to critically evaluate the information they encounter and recognise potential biases. Such cognitive defenses can empower individuals to question the sources of the information and report misleading content effectively. In the future of algorithms in information moderation, platforms should evolve toward more transparent, user-driven systems where algorithms are optimised not just for engagement but for accuracy and fairness. Incorporating advanced AI moderation tools, coupled with human oversight can improve the detection and reduction of harmful and misleading content. Collaboration between regulatory bodies, tech companies, and users will help shape the algorithms landscape to promote a healthier, more informed digital environment.
References:
- https://www.advancedsciencenews.com/misformation-spreads-like-a-nuclear-reaction-on-the-internet/
- https://www.niemanlab.org/2024/09/want-to-fight-misinformation-teach-people-how-algorithms-work/
- Press Release: Press Information Bureau (pib.gov.in)

Pretext
On 20th October 2022, the Competition Commission of India (CCI) imposed a penalty of Rs. 1,337.76 crores on Google for abusing its dominant position in multiple markets in the Android Mobile device ecosystem, apart from issuing cease and desist orders. The CCI also directed Google to modify its conduct within a defined timeline. Smart mobile devices need an operating system (OS) to run applications (apps) and programs. Android is one such mobile operating system that Google acquired in 2005. In the instant matter, the CCI examined various practices of Google w.r.t. licensing of this Android mobile operating system and various proprietary mobile applications of Google (e.g., Play Store, Google Search, Google Chrome, YouTube, etc.).
The Issue
Google was found to be misusing its dominant position in the tech market, and the same was the reason behind the penalty. Google argued about the competitive constraints being faced from Apple. In relation to understanding the extent of competition between Google’s Android ecosystem and Apple’s iOS ecosystem, the CCI noted the differences in the two business models, which affect the underlying incentives of business decisions. Apple’s business is primarily based on a vertically integrated smart device ecosystem that focuses on the sale of high-end smart devices with state-of-the-art software components. In contrast, Google’s business was found to be driven by the ultimate intent of increasing users on its platforms so that they interact with its revenue-earning service, i.e., online searches, which directly affects the sale of online advertising services by Google. It was seen that google had created a dominant position among the android phone manufacturers as they were made to have a set of google apps preinstalled in the device to increase the user’s dependency on google services. The CCI felt that Google had created a dominant position to which they replied that the same operations are done by Apple as well, to which the commission responded that apple is a phone and app manufacturer and they have Apple-owned apps in Apple devices only, but Google here in had made a pseudo mandate for android manufactures to have the google apps pre-installed which is, in turn, a possible way of disrupting the market equilibrium and violative of market practices. The CCI imposed a penalty of Rs. 1,337.76 for abusing its dominant position in multiple markets in India, CCI delineated the following five relevant markets in the present matter –

- The market for licensable OS for smart mobile devices in India
- The market for app store for Android smart mobile OS in India
- The market for general web search services in India
- The market for non-OS specific mobile web browsers in India
- The market for online video hosting platforms (OVHP) in India.
Supreme Courts Opinion
In October 2022, the Competition Commission of India (CCI) ruled that Google, owned by Alphabet Inc, exploited its dominant position in Android and told it to remove restrictions on device makers, including those related to the pre-installation of apps and ensuring exclusivity of its search. Google lost a challenge in the Supreme Court to block the directives, as the learned court refused to put a stay on the imposed penalty, further giving seven days to comply. The Supreme Court has said a lower tribunal—where Google first challenged the Android directives—can continue to hear the company’s appeal and must rule by March 31.
Counterpoint Research estimates that about 97% of 600 million smartphones in India run on Android. Apple has just a 3% share. Hoping to block the implementation of the CCI directives, Google challenged the CCI order in the Supreme Court by warning it could stall the growth of the Android ecosystem. It also said it would be forced to alter arrangements with more than 1,100 device manufacturers and thousands of app developers if the directives kick in. Google has been concerned about India’s decision as the steps are seen as more sweeping than those imposed in the European Commission’s 2018 ruling. There it was fined for putting in place what the Commission called unlawful restrictions on Android mobile device makers. Google is still challenging the record $4.3 billion fine in that case. In Europe, Google made changes later, including letting Android device users pick their default search engine, and said device makers would be able to license the Google mobile application suite separately from the Google Search App or the Chrome browser.
Conclusion
As the world goes deeper into cyberspace, the big tech companies have more control over the industry and the markets, but the same should not turn into anarchy in the global markets. The Tech giants need to be made aware that compliance is the utmost duty for all companies, and enforcement of the law of the land will be maintained no matter what. Earlier India lacked policies and legislation to govern cyberspace, but in the recent proactive stance by the govt, a lot of new bills have been tabled, one of them being the Intermediary Rules 2021, which has laid down the obligations nand duties of the companies by setting up an intermediary in the country. Such bills coupled with such crucial judgments on tech giants will act as a test and barrier for other tech companies who try to flaunt the rules and avoid compliance.