bleeping-computer · Crawled Jul 13, 2026
US and allies warn of Russian critical infrastructure attacks
2 Actors
Read original article ↗
AI Summary
Cybersecurity agencies from the US and allied nations have issued a joint advisory warning of Russian state-sponsored hackers, attributed to FSB Center 16, targeting critical infrastructure by exploiting misconfigured routers and known vulnerabilities. The threat actor scans for devices using default SNMP credentials and exploits CVE-2018-0171 in Cisco Smart Install to gain control of network devices. Sectors at risk include energy, healthcare, defense, and government services. The advisory emphasizes mitigation steps such as disabling vulnerable features, upgrading to SNMPv3, and blocking unauthorized protocols at firewalls.
AI-extracted · verify before operational use
Extracted Entities 2 found
MITRE ATT&CK TTPs 17 techniques
T1059.001 PowerShell · Execution T1003 OS Credential Dumping · Credential Access T1027 Obfuscated Files or Information · Defense Evasion T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1070.004 File Deletion · Defense Evasion T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1078.004 Cloud Accounts · Defense Evasion T1090 Proxy · Command And Control T1114 Email Collection · Collection T1136.001 Local Account · Persistence T1204.002 Malicious File · Execution T1556.005 Reversible Encryption · Credential Access T1558 Steal or Forge Kerberos Tickets · Credential Access T1558.003 Kerberoasting · Credential Access T1566 Phishing · Initial Access