Skip to content

Multinational Security Advisory Warns of Russia-Sponsored Network Attacks

Follow these recommended steps to secure routers against attacks.

Abstract vector lines and circles
Image by Tarry_Not on Pixabay

Russian state-sponsored attacks continue to exploit “poorly configured and vulnerable networking devices worldwide,” potentially compromising critical infrastructure, warns a recent multinational cybersecurity advisory.

The advisory — jointly issued by the US National Security Agency (NSA), CISA, and FBI, along with security and intelligence agencies across Europe, New Zealand, and Australia — strongly urges device owners and administrators to take the following recommended steps to secure routers against these attacks:

  • Disable Cisco Smart Install on all devices. The advisory notes that this feature is designed for initial router configuration and can introduce security risks if left enabled.
  • Implement SNMPv3 with “authPriv” configured to the most modern encryption standard that is supported by the device.
  • Use strong, unique passwords on network devices and configure credentials to be stored securely to prevent reuse of compromised passwords. On Cisco devices, use hashing type 8 for user credentials; avoid type 0, 4, and 7.
  • Deny inbound and outbound traffic on UDP port 69 (TFTP), TCP port 4786 (SMI), UDP ports 161 and 162 (SNMP), TCP/UDP ports 10161 and 10162 (SNMPv3) for all edge firewalls and devices.

Critical infrastructure sectors most at risk from these Russian state-sponsored attacks include: 

  • Communications
  • Defense industrial base
  • Energy
  • Financial services
  • State and local government services and facilities
  • Healthcare and public health systems

Learn more about these attacks and get additional technical details from the official CISA advisory.

Add ADMIN IT Infrastructure & Operations on Google