State-backed Russian hacker groups such as Berserk Bear and Energetic Bear infiltrate routers through outdated firmware and default configurations to gain long-term network access — not solely through zero-day exploits.
Russian hackers are targeting critical infrastructure via vulnerable routers—authorities in multiple countries warn of patching deficiencies across energy, communications, healthcare, and defense sectors.
CISA took over 48 hours to invalidate leaked AWS keys, ignored nine automatic security alerts, and had no defined incident reporting procedures for its own infrastructure.
CISA documents four actively exploited security vulnerabilities in widely used enterprise software, including a critical path-traversal flaw in Adobe ColdFusion with maximum CVSS rating.
Zero-Trust in OT succeeds better through concrete functional principles than abstract architecture models, and through focused measures at IT-OT interfaces such as jump hosts and remote access paths.