CISA, in collaboration with National Security Agency (NSA), Federal Bureau of Investigation (FBI), Defense Cyber Crime Center (DC3), and international partners, released a joint cybersecurity advisory, Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting. The advisory warns that Russian cyber threat actors are targeting vulnerable networking devices in critical infrastructure sectors globally, especially communications, defense industrial base, energy, financial services, government services and facilities, and healthcare and public health. For the HPH sector, the primary lesson from the joint advisory is that edge devices require the same level of rigorous asset inventory, patching, and configuration management as traditional IT systems.
Led by NSA, the advisory highlights how threat actors primarily leverage poorly configured routers but are also known to exploit common vulnerabilities and exposures (CVEs) to gain unauthorized access, exfiltrate sensitive configurations, and facilitate malicious activity. To defend against these threats, the advisory outlines actionable mitigation steps, such as:
- Restrict access to management interfaces and firewall devices
- Adopt stronger authentication and data encryption protocols
- Secure weak and vulnerable internet-facing systems
- Monitor for suspicious activity
The advisory outlines practical steps organizations can take to harden their networks against exploitation, such as upgrading device configurations, enabling stronger authentication protocols, and monitoring for suspicious activity. All network defenders and device owners are strongly encouraged to review the recommended mitigations and take immediate action to reduce risk.
For more information, read the advisory and visit CISA’s Russia Threat Overview and Advisories.