Summary

The NSA, CISA, FBI, and international partners released a joint Cybersecurity Advisory this week warning organizations about active targeting by the Russian Federal Security Service’s Center 16 — exploiting vulnerable and poorly configured networking devices across critical infrastructure sectors including defense, energy, communications, financial services, government, and healthcare.

The advisory, titled “Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting,” emphasizes that the entry points are almost entirely basic security failures: outdated firmware, default passwords, and exposed network management protocols (SNMP, Telnet, HTTP management interfaces). The attackers are not exploiting zero-days — they are walking through unlocked doors. The guidance calls for organizations to restrict access to management interfaces, adopt SNMPv3 and strong authentication, update firmware and software regularly, disable unnecessary remote management features, and monitor for suspicious activity.

Center 16 has been previously linked to espionage campaigns against NATO-member supply chains and has demonstrated sustained interest in maintaining quiet, long-term access to network infrastructure rather than destructive attacks.

Source

NSA Press Release
CISA Advisory
Decode39

Commentary

State-sponsored threat actors using default passwords and SNMPv1 as entry points is both embarrassing and completely predictable. The NSA advisory is essentially saying: your unlocked network closet is how a foreign intelligence service gets into your critical infrastructure. There is no exotic technique here — the sophistication is in the patience and the target selection, not the initial access.

For defenders, this is a useful forcing function to audit network device inventory. Check every router, switch, and firewall: firmware currency, SNMPv1/v2 disabled, management interfaces firewalled, default credentials rotated. These hygiene checks should be on quarterly rotation regardless of threat advisories. The fact that the NSA has to issue a formal joint advisory about this in 2026 suggests a lot of organizations still aren’t doing it.

By Allan