No Zero-Day Required: 19 Agencies Warn Russia’s FSB Is Walking Into Critical Infrastructure Through Default Router Passwords

There is a comforting story the industry tells itself about nation-state attackers: that they arrive with priceless zero-days and impossible tradecraft, and that getting breached by one is bad luck rather than bad hygiene. A joint advisory from nearly twenty government agencies just took that story out back.

According to the advisory — titled “Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting” and published July 13, 2026 as CISA alert AA26-194A — the NSA, CISA, the FBI, and the DoD Cyber Crime Center, together with 16 partner agencies across 13 countries including the UK’s NCSC, France’s ANSSI, Canada’s Cyber Centre, Australia’s ASD, and New Zealand’s NCSC, warn that cyber actors linked to the Russian Federal Security Service’s Center 16 continue to exploit vulnerable and poorly configured networking devices worldwide. Per the advisory, the campaign has touched networks across the communications, defense industrial base, energy, financial services, government facilities, and healthcare sectors. The NSA said in an accompanying statement that this is an ongoing issue affecting various U.S. and foreign networks across multiple sectors.

The technique is almost insultingly simple

Here is how BleepingComputer describes the method: the group scans internet-connected IP ranges for routers accepting default or common SNMP authentication strings, then issues commands using spoofed IP addresses to copy device configuration files and exfiltrate them via Trivial File Transfer Protocol to actor-controlled servers.

Read that again. No exploit. No malware. No zero-day. They ask the router for its configuration using a password that ships in the manual, and the router — helpful to a fault — hands it over. A device configuration file is a treasure map: credentials, network topology, VPN settings, ACLs, the lot. Nextgov reports the operators have also exploited Cisco’s Smart Install feature, web portals used to manage network devices, and at least two Cisco vulnerabilities, one of which was logged in CISA’s KEV catalog the same day.

The group is tracked by various vendors as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra — though the agencies caution that private-sector naming doesn’t map perfectly onto government attribution. The advisory frames this as a decade-plus pattern, building on a prior FBI public service announcement on the same actor.

Ensar Seker, CISO at SOCRadar, put the lesson plainly in comments on the advisory: nation-state attackers don’t always need a sophisticated zero-day to penetrate critical infrastructure — weak router configurations, default SNMP community strings, outdated firmware, and needlessly exposed legacy management protocols often provide everything they need.

What to do about it

  • Move to SNMPv3: Adopt SNMPv3 with authentication and privacy, and disable SNMPv1 and SNMPv2 entirely. This single change closes the primary door described in the advisory.
  • Kill the default community strings: Enforce strong, unique credentials on network devices — “public” and “private” are not passwords, they’re punchlines.
  • Disable Cisco Smart Install: If you aren’t actively using it, turn it off; it has been an attacker favorite for years.
  • Block the exfil paths at the edge: Filter TFTP, SMI, and SNMP at the firewall where they aren’t needed.
  • Patch the firmware: Keep networking software and firmware current so the known-vulnerability route closes alongside the misconfiguration route.
  • Alert on config copies: Watch for the SNMP operations that copy device configurations — legitimate use is rare and predictable, so anomalies stand out.

The outrage

Nineteen agencies across thirteen countries had to co-sign a document to tell the world’s critical infrastructure operators to change their router passwords. Sit with that. This is not a sophisticated adversary problem; it is a housekeeping problem that has been left unattended for so long that a foreign intelligence service built a decade-long collection program on top of it.

The genuinely maddening part is how cheap the fix is. There is no procurement cycle here, no rip-and-replace, no vendor to blame. SNMPv3, unique credentials, turn off Smart Install, block TFTP at the border. It is a boring afternoon of work standing between the FSB and your energy sector. Because the exploited weaknesses are configuration-based rather than software flaws requiring patches, router hygiene audits alone meaningfully shrink the attack surface — which is another way of saying we’ve been handing this away for free. Go audit your routers. The alternative is being a footnote in the next advisory.

Leave a Reply

Discover more from Cyber Outrage

Subscribe now to keep reading and get access to the full archive.

Continue reading