← All stories
● Covered by 3 sources · 3 reportsMedium impact

US and Allied Nations Warn of Russian Router-Based Cyberattacks on Critical Infrastructure

🔄 Updated 80d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • US and allies warn of Russian router-based cyberattacks.
  • FSB-linked groups target critical infrastructure globally.
  • Vulnerable routers used to access sectors like energy, healthcare.
  • SNMP vulnerabilities exploited for unauthorized access.
  • Mitigation strategies provided by cybersecurity agencies.

Joint Advisory on Cyber Threats

The United States, along with several allied countries, has issued a joint advisory warning of Russian cyber actors targeting vulnerable routers to infiltrate critical infrastructure. The agencies involved include the NSA, FBI, CISA, and analogous bodies from eight other nations, pointing to an extensive cooperative effort to address these security concerns.

Specifics of the Cyber Attacks

The attacks are attributed to Russian Federal Security Service (FSB) Center 16 hackers, operating under various names such as Berserk Bear and Energetic Bear. These actors are actively scanning IP ranges to compromise routers with default SNMP settings, allowing them to execute unauthorized configuration copies and data exfiltration.

Targeted Sectors and Vulnerabilities

Critical infrastructure sectors, including energy, healthcare, and communications, are particularly at risk. The advisory notes past instances of exploitation, specifically referencing the Smart Install vulnerability in Cisco products, CVE-2018-0171. This ongoing threat highlights the need for stringent security measures on networking devices.

Global Cybersecurity Efforts

To counter this threat, the joint advisory provides mitigation strategies, emphasizing the importance of securing home and small office routers. Efforts by Google and other companies to disrupt botnets formed by compromised routers are noted, marking an ongoing battle to maintain device and network integrity.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The US and allied nations have issued a warning about Russian APT actors exploiting poorly secured networking devices, particularly routers, to target critical infrastructure systems. This alarming trend jeopardizes communication, energy, and healthcare sectors by leveraging known vulnerabilities in such devices.

The US government has issued a warning about Russian state hackers exploiting vulnerable home and small office routers to launch attacks against sensitive organizations. This ongoing threat, which involves mass compromises and botnet operations, highlights how poor router configuration can facilitate unauthorized access and control.

Cybersecurity agencies from the US and eight allied nations warn that Russian state hackers are targeting vulnerable routers to compromise critical infrastructure. The advisory highlights risks across various sectors, including energy and healthcare, and offers mitigation strategies.