Skip to main content
  1. Home
  2. Computing
  3. News

Russian hackers keep finding their way into critical networks through neglected routers

A multinational warning says outdated firmware, weak passwords, and insecure settings are giving state-backed attackers an easy opening

Add as a preferred source on Google
A Wi-Fi router next to a laptop.
Getty Images

Russian state-backed hackers have spent more than a decade exploiting a stubborn weakness in critical infrastructure networks. Organizations are still leaving poorly configured and outdated routers exposed to the internet.

In a joint cybersecurity advisory, the NSA, CISA, FBI, and international partners warn that hackers linked to Center 16 of Russia’s Federal Security Service are continuing to target vulnerable networking equipment. Energy, healthcare, and government networks are among the sectors facing the highest risk.

Recommended Videos

One forgotten device can expose credentials and reveal how a much larger network fits together.

How the routers are being exposed

The hackers scan internet-facing networks for routers running poorly secured versions of Simple Network Management Protocol, better known as SNMP. Devices that accept common or default authentication strings can be instructed to copy their configuration files and send them to attacker-controlled servers.

Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, targeting devices across critical infrastructure sectors. These vulnerabilities can give hostile actors access to the systems that… pic.twitter.com/K5Po1v87Fu

— FBI Phoenix (@FBIPhoenix) July 14, 2026

Older Cisco equipment presents another route inside. The group has exploited known vulnerabilities and abused Cisco Smart Install, a feature that may remain enabled long after deployment. None of this requires some dazzling Hollywood hack when obsolete protocols and weak configurations are already exposed.

What attackers gain from a router

Router configuration files can contain credentials and show how a network is organized. Once copied, that information helps the hackers identify other systems and choose where to concentrate their efforts.

The campaign focuses on gathering access instead of causing immediate disruption. That quieter approach can keep a compromise hidden while giving the Russian government information it could use as its strategic priorities change. The router is only the first target, and the useful prize sits behind it.

How organizations can close the door

The agencies recommend replacing outdated routers, installing current firmware, and disabling Cisco Smart Install. Network defenders should also move from the obsolete SNMPv1 and SNMPv2 protocols to SNMPv3, which adds stronger authentication and encryption.

Organizations should use strong, unique passwords and restrict management protocols to trusted devices. Suspicious requests and unusual local-account logins also need monitoring.

These are basic security measures, but skipping them means state-backed hackers may never need their cleverest tools. Organizations should audit their internet-facing networking equipment now, starting with any router that no longer receives security updates.

Paulo Vargas
Paulo Vargas is an English major turned reporter turned technical writer, with a career that has always circled back to…
MIT researchers found a new Spectre attack that can slip past Intel and AMD defenses
AMD Ryzen CPU inside a socket installed on a motherboard

Spectre has been haunting CPU security since 2018, and MIT researchers have now found another way to make it misbehave. The new TONTOU attack can bypass some of the defenses Intel and AMD have added over the years by exploiting a tiny gap in how those protections work. The research comes from Daniël Trujillo and Mengjia Yan at MIT's Computer Science and Artificial Intelligence Laboratory (CSAIL). Their findings show that even after a processor wipes or isolates information used by its branch predictor, there can be a brief window before that information is actually used. TONTOU, short for Time-of-Neutralization to Time-of-Use, attacks precisely that gap.

The tiny gap that TONTOU exploits

Read more
Microsoft accidentally gave Windows 11 users another OneDrive app, and you can’t easily remove it
Microsoft says the wider-than-intended rollout was an accident, but removing the app currently means removing OneDrive too.
Microsoft OneDrive Featured Graphic

Windows 11 users have been getting a new OneDrive app whether they asked for it or not. The problem? Microsoft says it wasn't supposed to happen. Microsoft has confirmed that its OneDrive Photos app was rolled out to Windows 11 PCs more broadly than intended, including enterprise machines where the app isn't even designed to work. The company says it is now working on a fix, but there's an awkward catch: users currently can't uninstall OneDrive Photos without removing the main OneDrive app too.

So, what exactly got installed?

Read more
Apple Reminders sucked for project management until I learned this feature
Your checklist deserves better. Here's how to turn Reminders into a proper Kanban board.
Apple reminders on Mac

For the longest time, I used Apple Reminders only for capturing quick tasks. Thanks to its Siri integration, Reminders let me add tasks quickly so nothing would fall through the cracks. However, when it came to managing big projects, I always moved to a more powerful task manager like OmniFocus or Things 3. 

That changed the day I stumbled onto the Column view. Apple added this feature with the iOS 17 and macOS Sonoma updates, and somehow I completely missed it. But once I discovered and got the hang of it, Reminders finally started to feel like a real project management tool instead of a glorified sticky note.

Read more