The most striking line in the 13 July 2026 joint advisory is not about a novel exploit. It is that a state intelligence service, with more than a decade of practice, keeps succeeding by scanning the open internet for routers still protected by default or weak passwords. The tradecraft is patient; the entry point is negligence. That combination is precisely what governance is supposed to close, and precisely what it keeps leaving open.
What the advisory says
The NSA, FBI and CISA, alongside agencies from a dozen partner countries — Australia’s ASD among them, with the UK, Canada, New Zealand and several European states — issued a joint advisory titled, plainly, Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting. It attributes the activity to FSB Center 16, a signals-intelligence and cyber unit tracked across the industry under a menagerie of names: Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard and Static Tundra.
The targeting is not opportunistic noise. It concentrates on the sectors that keep a country running: communications, the defence industrial base, energy, financial services, government facilities and healthcare. Center 16 has been working these targets for more than ten years.
The same day the advisory landed, the EU and the UK imposed sanctions on Russian intelligence officers, hackers and front companies over a years-long cyber-espionage campaign, and formally attributed the late-2025 attacks on Poland’s energy infrastructure to Center 16 — an attack the UK stated could have affected half a million citizens had it succeeded. The advisory and the sanctions are two halves of one message: attribution plus consequence.
The attack path — and how ordinary it is
Strip the campaign to its mechanics and it reads like a penetration-testing checklist the defender failed. The adversary scans the internet for exposed network devices, finds ones running weak or default SNMP credentials or unpatched firmware, and turns a perimeter router into a foothold — then moves laterally into the network it guards.
Analysts reviewing the campaign made the point bluntly: legacy operational-technology environments still lean on default credentials, exposed management interfaces and flat network architectures. The advisory also notes Center 16’s techniques overlap with those of other state actors, including China-linked groups — so the same weak router is a shared doorway for multiple adversaries, not a Russia-specific problem.
Why this belongs on the Australian agenda
The ASD did not merely receive this advisory — it co-authored it. That matters for accountability. The same themes run through ASD’s own recent Cyber Threat Reporting, which named replacing legacy IT, managing third-party risk and improving logging among its priority moves for national resilience. Router hygiene is where those abstractions become a specific, testable task.
For any organisation captured by the Security of Critical Infrastructure (SOCI) Act, an exposed, unpatched perimeter device is not just a technical finding — it is a gap against a positive security obligation. For APRA-regulated entities, CPS 234 makes the same device a control deficiency against the requirement to secure information assets by criticality. And nearly every mitigation the advisory recommends maps directly onto the Essential Eight: patch applications and operating systems, and restrict administrative privileges.
Prevention — A Board-Verifiable Checklist
- Inventory every network device. Routers, switches, firewalls — you cannot secure or patch what you have not counted. This is SOCI asset-register discipline applied to the perimeter.
- Kill default and weak SNMP community strings. Move to SNMPv3 with authentication and encryption. Default strings are the single most-used doorway in this campaign.
- Patch firmware on a governed cadence. Unpatched, internet-exposed devices are the recurring root cause. Tie this to Essential Eight patching maturity and evidence it.
- Retire insecure protocols. Disable TFTP where possible; replace it with SCP or SFTP. Close exposed management interfaces to the internet entirely.
- Segment the network. Use identity-based micro-segmentation so a compromised edge device cannot become free lateral movement into OT and critical systems.
- Log and monitor the edge. Device-level logging turns a silent foothold into a detectable event — aligned with ASD’s logging priority.
None of this is novel, and that is exactly why it is a governance story, not a technology story. The adversary is betting these controls exist on paper and not in the config. The organisations that close the campaign are the ones that can produce evidence — a current device inventory, an SNMPv3 rollout record, a patch cadence with dates — rather than an intention. That evidence gap is where an external exposure assessment earns its place: it shows a Board what an FSB scanner already sees.
Sources & references
- CISA — Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting, Advisory AA26-194A (13 July 2026)
- CISA — Joint press release with NSA, FBI, DC3 and international partners
- Joint Cybersecurity Advisory — full text; authoring agencies incl. ASD’s ACSC (PDF, media.defense.gov)
- APRA — Prudential Standard CPS 234 Information Security