The United States and its security allies are warning that Russian attacks on critical infrastructure are escalating against “misconfigured and vulnerable network devices around the world.”
The NSA, FBI, CISA and 15 allied agencies warn that Russian FSB Center 16 is exploiting weak/default credentials and old Cisco vulnerabilities to compromise critical infrastructure devices. The advisory highlights CVE‑2018‑0171 (Smart Install DoS/RCE) and CVE‑2008‑412813 (CSRF in Cisco IOS 12.4) as examples of vulnerabilities still being exploited. TTP overlaps with Chinese groups, but attribution […]










