{"id":16460,"date":"2026-07-14T01:53:54","date_gmt":"2026-07-14T01:53:54","guid":{"rendered":"https:\/\/newestek.com\/?p=16460"},"modified":"2026-07-14T01:53:54","modified_gmt":"2026-07-14T01:53:54","slug":"governments-to-enterprises-improve-your-router-security-hygiene","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=16460","title":{"rendered":"Governments to enterprises: Improve your router security hygiene"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p class=\"wp-block-paragraph\">Global security agencies say enterprises must clean up their act as Russian government-sponsored attackers exploit weaknesses in routers.<\/p>\n<p class=\"wp-block-paragraph\">According to a new multinational <a href=\"https:\/\/www.ic3.gov\/CSA\/2026\/260713.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">cybersecurity advisory<\/a>, cyberattackers continue to exploit inadequately-protected and\/or poorly-configured network devices via age-old tactics. Threat actors scan for weakened devices, typically routers, allowing them to \u201copportunistically\u201d compromise critical infrastructure networks, according to the bulletin from 19 federal agencies across North America, the UK, Europe, and Australia.<\/p>\n<p class=\"wp-block-paragraph\">They then transfer configuration files to servers they control. These files, containing plaintext or weakly-encoded information like credentials, or details about the organization\u2019s network, hold most of the potential value, noted <a href=\"https:\/\/www.infotech.com\/profiles\/seva-ioussoufovitch\" target=\"_blank\" rel=\"noreferrer noopener\">Seva Ioussoufovitch<\/a>, a senior research analyst at Info-Tech Research Group.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIt might sound simple, but this tactic has been exploited for well over a decade, and is clearly still effective,\u201d he said.<\/p>\n<h2 class=\"wp-block-heading\" id=\"how-snmp-attacks-work\">How SNMP attacks work<\/h2>\n<p class=\"wp-block-paragraph\">To begin their attack, state-sponsored cybercriminals send requests via the standard Simple Network Management Protocol (SNMP) framework that supports device-network information exchange, which allows them to scan for weak, insecure devices still using older SNMPv1 or SNMPv2 protocols that accept common or default \u201ccommunity strings\u201d for authentication. These strings are typically shared passwords, with predictable, public defaults that might have been left untouched by admins. Additionally, many of these devices may remain in their basic router configurations.<\/p>\n<p class=\"wp-block-paragraph\">Using spoofed IP addresses, threat actors instruct SNMP agents running on these devices to copy their configurations to a file (typically \u201cconfig.bkp\u201d or \u201coutput.txt\u201d), then transfer that file to virtual private servers (VPSs) that they control. In addition, cybercriminals are exploiting <a href=\"https:\/\/www.csoonline.com\/article\/4168484\/your-refresh-plan-has-a-cve-blind-spot.html\" target=\"_blank\">common vulnerabilities and exposures<\/a> (CVEs) in Cisco devices, as well as in the Cisco\u2019s Smart Install (SMI) tool.<\/p>\n<p class=\"wp-block-paragraph\">Actors have exploited, at the very least, <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2018-0171\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2018-0171<\/a> (published in 2018) and <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2008-4128\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2008-4128<\/a> (published in 2008), according to the bulletin. Both of these targeted <a href=\"https:\/\/www.csoonline.com\/article\/4043721\/russian-hackers-exploit-old-cisco-flaw-to-target-global-enterprise-networks.html\" target=\"_blank\">Cisco routers<\/a>, giving remote, unauthenticated attackers the ability to execute arbitrary code, take unauthorized actions, or cause a denial of service (DoS).<\/p>\n<p class=\"wp-block-paragraph\">Notable groups using this method are known to the security community as \u201cBerserk Bear,\u201d \u201cCrouching Yeti,\u201d \u201cDragonfly,\u201d \u201cEnergetic Bear,\u201d \u201cGhost Blizzard,\u201d and \u201cStatic Tundra.\u201d According to the bulletin, the industries most vulnerable to Russian state-sponsored cyber actors include communications, energy, financial services, defense industrial bases, healthcare and public health facilities, and government services and facilities.<\/p>\n<h2 class=\"wp-block-heading\" id=\"a-set-and-forget-approach-even-in-2026\">A set-and-forget approach, even in 2026<\/h2>\n<p class=\"wp-block-paragraph\">The problem with router hygiene is that devices are susceptible to a \u201cconfluence of typical enterprise shortcomings\u201d when it comes to operationalizing security, noted Info-Tech\u2019s Ioussoufovitch.<\/p>\n<p class=\"wp-block-paragraph\">\u201cMany organizations still take a set-it-and-forget-it approach to routers, and don\u2019t track them like they would an endpoint,\u201d he said.<\/p>\n<p class=\"wp-block-paragraph\">Compounding this risk is the fact that routers are typically critical to business continuity, which increases the necessity of keeping their security up-to-date. To make things worse, in some cases, it might also be unclear who\u2019s in charge of device security. \u201cSecurity points to the network team and they\u2019re pointing right back at security,\u201d Ioussoufovitch noted.<\/p>\n<p class=\"wp-block-paragraph\">As well, many organizations continue to rely on legacy hardware that may be unsupported, but that the business is unwilling to replace.<\/p>\n<p class=\"wp-block-paragraph\">Ultimately, Ioussoufovitch said, \u201cnetwork security just doesn\u2019t seem to be receiving the same amount of attention as the usual areas of focus (like endpoints).\u201d<\/p>\n<h2 class=\"wp-block-heading\" id=\"recommendation-move-away-from-older-protocols-and-devices-immediately\">Recommendation: Move away from older protocols and devices immediately<\/h2>\n<p class=\"wp-block-paragraph\">Specifically, the agencies urged security teams and network admins to upgrade to SNMPv3, enforce secure passwords, disable Cisco Smart Install, and block SNMP and common file transfer methods \u201cat the firewall.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Enterprises should immediately disable SNMPv1 and SNMPv2, which are \u201clegacy protocols and should no longer be needed on current devices.\u201d In instances where they are still deemed necessary, shift from default settings to grant read-only access (no read-write access).<\/p>\n<p class=\"wp-block-paragraph\">SNMPv3 should be employed with <em>authPriv<\/em> configured to the \u201cmost modern encryption standard,\u201d the bulletin advised. SNMPv3 adds strong authentication and data encryption unavailable in previous versions, and has more securely encoded parameters to authenticate and encrypt data.<\/p>\n<p class=\"wp-block-paragraph\">\u201cMoving to SNMPv3, which offers stronger authentication and encryption, is a clear, actionable step security teams need to prioritize now,\u201d Ioussoufovitch agreed.<\/p>\n<p class=\"wp-block-paragraph\">The government agencies urged enterprises to use strong, unique passwords for local accounts on network devices, and to monitor for unusual credentials that do not match standard naming conventions, or misconfiguration in logs or intrusion detection systems (IDS). Networks should support multi-factor authentication (MFA), and admins should enforce allow lists for management protocols like SNMP.<\/p>\n<p class=\"wp-block-paragraph\">Additionally, enterprises should update network device software, retire end-of-life devices, and disable Cisco Smart Install on all machines once initial configuration is complete, as this introduces serious <a href=\"https:\/\/www.csoonline.com\/article\/4195710\/jurassic-park-cybersecurity-and-the-dangerous-myth-of-control.html\" target=\"_blank\">security issues<\/a> when it inadvertently remains enabled, the agencies said.<\/p>\n<h2 class=\"wp-block-heading\" id=\"network-security-must-improve-across-the-board\">Network security must improve across the board<\/h2>\n<p class=\"wp-block-paragraph\">The advisory is a signal that enterprises may be underinvesting in network security, noted Ioussoufovitch. Admins and security leaders should be asking these questions:<\/p>\n<ul class=\"wp-block-list\">\n<li>Do they have decent network detection and response capabilities in place?<\/li>\n<li>Are they applying analytics and anomaly detection to network traffic patterns?<\/li>\n<li>Have they incorporated micro-segmentation across the enterprise environment to limit risks posed by any individual router?<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">\u201cGetting at least some of these proactive measures in place, while taking a more disciplined approach to the tracking and replacement of EOL devices, can help security and network teams finally start making some headway against these types of threats,\u201d said Ioussoufovitch.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/dbshipley\/\" target=\"_blank\" rel=\"noreferrer noopener\">David Shipley<\/a> of Beauceron Security agreed that enterprise networking equipment security must be improved, but said that\u2019s more on the vendors than the critical infrastructure providers. Vendors should be shipping products that are secure by default; customers shouldn\u2019t have to be going back and turning these features on.<\/p>\n<p class=\"wp-block-paragraph\">He added that it would be great to see Salt Typhoon-proof levels of device security and authentication. \u201cRight now, it\u2019s been trivial for them to pwn networking gear,\u201d he said.<\/p>\n<p class=\"wp-block-paragraph\">While the guidance is important and will help, Shipley said, \u201cbuilding better and shipping secure by default would do even more.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Global security agencies say enterprises must clean up their act as Russian government-sponsored attackers exploit weaknesses in routers. According to a new multinational cybersecurity advisory, cyberattackers continue to exploit inadequately-protected and\/or poorly-configured network devices via age-old tactics. Threat actors scan for weakened devices, typically routers, allowing them to \u201copportunistically\u201d compromise critical infrastructure networks, according to the bulletin from 19 federal agencies across North America, the&#8230; <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=16460\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16460","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16460","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16460"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16460\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16460"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16460"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16460"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}