cisatrade-pressNewsThe Broadside1 min read

FSB Center 16 exploits old Cisco flaws in critical infrastructure

The advisory reads less like new tradecraft than an inventory of unforced errors: weak passwords, exposed portals and obsolete device features.


TL;DR

CyberScoop reports that the National Security Agency and 12 allied governments warned Monday that Russia’s FSB Center 16 is still compromising vulnerable network devices across defense industrial base, communications, energy, finance, government facilities and health care networks. The group has exploited default or weak passwords, Cisco Smart Install, web portals and old Cisco flaws including CVE-2008-4128 and CVE-2018-0171. For defenders, the Monday work is familiar: disable Smart Install, harden authentication and watch local-account logins.

This is a joint government warning, but the operational story is drearily concrete. FSB Center 16, also tracked as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard and Static Tundra, is not being described as winning with exotic implants. CyberScoop reports that U.S. and allied authorities say the Russian service is scanning for exposed routers, default or weak passwords, Cisco Smart Install, web portals and aging Cisco vulnerabilities, including CVE-2008-4128 and CVE-2018-0171.

That matters for critical infrastructure because network devices sit in the awkward space between IT inventory and infrastructure dependency. They are everywhere, they often stay in service too long, and they are easy to treat as plumbing until an intelligence service turns them into access. NSA said the activity has affected U.S. and foreign networks across sectors including the defense industrial base, communications, energy, financial services, government facilities and health care.

The defender action is not mysterious. Disable Cisco Smart Install where it is still enabled. Replace weak authentication and passwords. Monitor for unusual credentials and local-account logins. The uncomfortable part is that this advisory follows an FBI alert from roughly a year ago about the same group targeting end-of-life networking devices running Cisco Smart Install. At that point, the gap is not awareness. It is asset ownership, refresh funding and the boring discipline of killing features that should not still be reachable from the internet.


Published ·Deep Fathom