CVE Tools

US and allies warn of Russian critical infrastructure attacks

BleepingComputerBy Sergiu Gatlan

AdvisoryNSABerserk Bear

Our summary

Cybersecurity agencies from the US and eight other nations have jointly warned that Russian state-backed hackers are targeting misconfigured and vulnerable routers to breach critical infrastructure networks. The advisory, authored by the NSA, FBI, CISA, and partners from Australia, the UK, Canada, and others, identifies several hacking groups—Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra—as responsible for scanning for weak SNMP credentials and using spoofed IPs to steal router configurations. These attacks pose a serious threat to sectors like energy, communications, healthcare, and government services. Agencies recommend upgrading to SNMPv3, disabling unused features like Cisco Smart Install, enforcing strong passwords, and blocking unnecessary traffic at firewalls.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store