US and allies warn Russian FSB-linked hackers are targeting critical infrastructure routers and Cisco devices

The US and allied governments warned that Russian state-backed hackers are breaking into routers and other network devices at critical infrastructure organizations around the world. The joint advisory says FSB Center 16-linked actors including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra are abusing Simple Network Management Protocol (SNMP) to copy device configurations off networks and are also exploiting known Cisco flaws CVE-2008-4128 and CVE-2018-0171 for code and command execution. Targeted sectors include communications, defense, energy, finance, government, and healthcare.
Why it matters: Organizations running internet-exposed or poorly secured routers may already be at risk, especially in critical infrastructure. Defenders should urgently disable Cisco Smart Install, turn off SNMPv1/v2, use SNMPv3, restrict management access, and patch affected Cisco devices.

Sources

US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers
Ionut Arghire 2026.07.14 100% relevant
This article establishes a distinct multi-country advisory about ongoing Russian router-focused intrusions against critical infrastructure, with specific TTPs and Cisco CVEs that do not match a single existing tracked event.
← Back to all stories