logo

Russian state cyber group Static Tundra exploiting Cisco devices, FBI warns

ID: c07e3692-4b4c-5dd9-890e-2b66885432d1

STIX ID: report--c07e3692-4b4c-5dd9-890e-2b66885432d1

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2025-08-20

Date Updated: 2026-05-01

...
...

The FBI and Cisco Talos warn that the Russian FSB-linked group Static Tundra is actively exploiting CVE-2018-0171 in unpatched and end-of-life Cisco Smart Install devices to harvest device configuration files, establish long-term persistence (including via the SYNful Knock implant), and pivot into victim networks across telecommunications, higher education, manufacturing and critical infrastructure worldwide; stakeholders are urged to patch, disable Smart Install, or seek assistance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.