Russian State Attackers Exploiting Misconfigured Routers, New Multi-nation Advisory Warns
Russian state-sponsored actors are compromising poorly secured routers and networking devices around the world, with critical infrastructure organisations among the primary targets, reveals a new joint cybersecurity advisory from 20 government agencies.
The advisory attributes the activity to cyber actors associated with the Russian Federal Security Service (FSB) Center 16, saying the group continues to exploit “poorly configured and vulnerable networking devices worldwide,” opportunistically targeting organisations across multiple critical infrastructure sectors.
According to the advisory, communications, defence, energy, financial services, government, and healthcare organisations face the greatest risk.
The campaign is being tracked across the cybersecurity industry under several names, including Berserk Bear, Energetic Bear, Dragonfly, Ghost Blizzard, Crouching Yeti, and Static Tundra, although the agencies note that vendor attribution does not always align exactly.
Attackers are abusing weak router configurations
Instead of relying on software vulnerabilities alone, the attackers are primarily exploiting insecure router configurations.
The advisory said the...
Copyright of this story solely belongs to informationsecuritybuzz.com. To see the full text click HERE