logo

Russian State-Sponsored Attackers Exploit Cisco Routers

ID: c8d90af2-b7a5-53db-bbfa-065128495016

STIX ID: report--c8d90af2-b7a5-53db-bbfa-065128495016

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2026-03-18

Date Updated: 2026-07-17

...
...

**Executive Summary:** The advisory describes how CVE-2017-6742, an SNMP buffer overflow in affected Cisco IOS and IOS XE versions, has been exploited by APT28 to deploy the Jaguar Tooth malware that patches authentication functions for backdoor access and performs automated device reconnaissance and TFTP exfiltration; the report lists affected MIBs/versions, device exposure estimates, recommended mitigations (restrict SNMP, monitor hosts, and apply patches), and emphasizes urgent remediation to prevent unauthorized control of routers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.