Russian State Hackers Target Vulnerable Routers Worldwide, Joint Advisory Warns
ID: db32d5af-cdc2-5746-869e-e7e015e01a04
STIX ID: report--db32d5af-cdc2-5746-869e-e7e015e01a04
Feed Name: Infosecurity Magazine (News)
Multiple national cybersecurity agencies warn that Russian state-sponsored FSB Center 16 (aka Berserk Bear/Static Tundra) is actively hunting vulnerable routers worldwide by scanning for weak/default SNMP credentials and sometimes exploiting known Cisco vulnerabilities (notably CVE-2018-0171) to exfiltrate configurations via TFTP; the UK and EU have attributed late-2025 destructive attacks on Poland's energy grid to the group, issued sanctions against individuals/entities involved, and flagged the use of Lumma Stealer-derived credentials in espionage operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
