US and allied Governments’ Recommendations: Securing Network Devices Against Russian APT Groups
ID: ea6361e2-c4bd-5b07-8d5f-53bec61bf112
STIX ID: report--ea6361e2-c4bd-5b07-8d5f-53bec61bf112
Feed Name: Security Affairs
US and allied governments warn that Russia-linked FSB Center 16 cyber actors are actively scanning and exploiting poorly configured routers and network devices worldwide—using SNMP with default community strings, spoofed requests, TFTP/FTP exfiltration, and known Cisco vulnerabilities (including CVE-2018-0171 and CVE-2008-4128)—to compromise critical infrastructure across communications, defense, energy, finance, government, and healthcare sectors; the advisory lists detection and mitigation steps such as disabling Cisco Smart Install, migrating to SNMPv3, restricting management access, blocking unnecessary ports, updating firmware, and replacing unsupported devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
