US and allies warn of Russian critical infrastructure attacks
Cybersecurity agencies from the US and eight other nations have jointly warned that Russian state-backed hackers are targeting misconfigured and vulnerable routers to breach critical infrastructure networks. The advisory, authored by the NSA, FBI, CISA, and partners from Australia, the UK, Canada, and others, identifies several hacking groups—Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra—as responsible for scanning for weak SNMP credentials and using spoofed IPs to steal router configurations. These attacks pose a serious threat to sectors like energy, communications, healthcare, and government services. Agencies recommend upgrading to SNMPv3, disabling unused features like Cisco Smart Install, enforcing strong passwords, and blocking unnecessary traffic at firewalls.