Back to the desk

Advisory summary

Nineteen agencies warn FSB Center 16 is exploiting poorly configured routers worldwide

Severity: HighGlobalAdvisory2026-0713-FS02 min readBy Vivek Kumar
Conceptual illustration: a router with a glowing shield over its network ports. Text: ROUTER SECURITY ALERT.

AI-generated editorial illustration by CyberShitty. Not a photograph or a document from the organisations named.

Joint advisory AA26-194A says Russia's FSB Center 16 abuses default SNMP settings and known Cisco flaws to copy router configurations, and urges operators to harden, patch or replace network devices.

01 / What happened

On 13 July 2026, the US National Security Agency, CISA, the FBI and the Department of Defense Cyber Crime Center published joint advisory AA26-194A, titled Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting, with fifteen partner agencies from twelve other countries.

The co-sealing partners are Australia's ASD's ACSC, Canada's Cyber Centre, NCSC-NZ, NCSC-UK, the Czech Republic's NÚKIB, Denmark's Defence Intelligence Service, Estonia's Foreign Intelligence Service and Information System Authority, Finnish Defence Intelligence and the Finnish Security and Intelligence Service, France's ANSSI, Italy's AISE and AISI, Poland's Military Counterintelligence Service and Sweden's NCSC.

The advisory attributes the activity to Center 16 of Russia's Federal Security Service (FSB), tracked by industry under names including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard and Static Tundra, and describes more than a decade of its operations against network devices.

02 / Why it matters

According to the advisory, the actors mainly look for routers and other networking equipment left with default or weak settings, especially SNMP services that accept default community strings. Once they find one, they use SNMP to make the device export its configuration and send it to infrastructure they control. Where available, they also exploit known Cisco vulnerabilities, including CVE-2018-0171 in the Smart Install feature and CVE-2008-4128, which affects only end-of-life Cisco devices.

The campaign relies less on new exploits than on routers nobody has reconfigured in years.

Router configurations can reveal network layout, credentials and trust relationships, giving an intelligence service a durable foothold for further collection.

03 / Who is exposed

The agencies say targeting is global and spans six critical infrastructure sectors:

  • Communications
  • Defense industrial base
  • Energy
  • Financial services
  • Government services, particularly state and local
  • Healthcare and public health

Organisations most at risk are those running internet-reachable routers with SNMPv1 or v2 enabled, default community strings, Smart Install left on, or end-of-life hardware.

04 / Confirmed vs. claimed

Confirmed (per the advisory): attribution to FSB Center 16 by the nineteen authoring agencies; exploitation of default SNMP configurations and the two CVEs above; the six targeted sectors.

Not stated: the advisory does not give a count of compromised devices or name victim organisations, and this summary does not add any.

05 / What to do now

The advisory's recommended mitigations include:

  • Disable Cisco Smart Install on all devices.
  • Move to SNMPv3 with authentication and encryption (authPriv) and disable SNMPv1 and v2; replace default community strings and restrict SNMP to read-only where possible.
  • Use strong, unique local passwords and strong password hashing (the advisory recommends Type 8 on Cisco devices).
  • Restrict management protocols with access control lists, limit management to dedicated management networks, and block TFTP, Smart Install and SNMP ports at the network edge.
  • Use centralised authentication with multi-factor authentication where feasible, and alert on local account logins and unusual SNMP write requests.
  • Patch firmware promptly and replace end-of-life devices.
  • Eligible US organisations can use CISA's free Cyber Hygiene services or, for the defense industrial base, NSA's DIB Cybersecurity Services.

Source log / 2026-0713-FS

More from the archive