← Knowledge Center
Advisory

CISA Warns of Russian FSB Center 16 Exploiting Weak Router Configs and Credentials

A joint advisory from NSA, CISA, FBI, DC3 and international partners warns that Russian FSB Center 16 cyber actors continue a decade-plus campaign of opportunistically compromising poorly configured and vulnerable networking devices across critical infrastructure worldwide. The advisory expands on prior FBI warnings by detailing additional tactics, techniques, and procedures to help defenders identify and counter the activity.

From an identity and access standpoint, the relevant risk centers on weak device authentication: default or reused credentials, exposed management protocols, and legacy configurations that let attackers gain footholds and harvest credentials for further network access. Compromised edge devices frequently serve as pivot points into internal networks and directory services.

What to take away: audit networking devices for default/weak credentials, disable unused management services, and treat router and switch access controls as part of your broader identity hygiene—edge device compromise is a common precursor to deeper credential theft and lateral movement.

Primary source

CISA Cybersecurity Advisories

Read at cisa.gov ↗

Summary by AD Argus. We publish our own analysis with attribution and a link to the original report; always consult the primary source for authoritative detail.