Bottom line: State-backed Russian hacker groups such as Berserk Bear and Energetic Bear infiltrate routers through outdated firmware and default configurations to gain long-term network access — not solely through zero-day exploits.
CISA, FBI and NSA warn jointly with eight allied nations of Russian state hackers exploiting vulnerable and misconfigured routers to penetrate critical infrastructure and steal sensitive network information.
The U.S. cybersecurity agency CISA has issued a security warning together with the FBI, NSA and eight partner nations. The addressees are Russian actors from the groups Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard and Static Tundra, who deliberately infiltrate vulnerable and misconfigured network devices — particularly routers — at the perimeter of corporate networks. The goal is to spy on and obtain more sensitive network information as well as establish long-term access to target networks.
Ensar Seker, research director at SOCRadar, clarifies: State-backed attackers do not always require sophisticated zero-day vulnerabilities. Often outdated firmware, default interfaces or unprotected protocols suffice. Router configuration files represent high-value information for attackers, as they contain network topologies, passwords, VPN settings and internal IP addresses. This data enables cybercriminals to penetrate deeper into systems undetected. Routers and network devices are frequently overlooked in security audits and should be treated as highly critical assets — a single compromised device can serve as a starting point for ongoing espionage or sabotage.
Primary targets of the attacks are the energy, telecommunications, defence, financial services, healthcare and government sectors. The authorities recommend the following countermeasures: complete inventory of all internet-connected devices, replacement of outdated protocols, removal of default passwords and continuous firmware updates. In parallel, the Council of the European Union has imposed sanctions against nine individuals and four organisations supporting Russian cyberattacks — including so-called bulletproof hosting providers such as Media Land LLC and ML.Cloud as well as actors involved in the development of malware such as the banking trojan TrickBot or the ransomware Conti.
Source: www.it-daily.net · Published 15 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.