Router Hygiene as National Defence.
The FSB Center 16 campaign, and what it demands of your Board.

Could you answer the questions below — today, with confidence? Most organisations cannot. A passive external assessment is where the honest answers begin: what you expose to the outside world, and who owns that risk.

Assess Your Exposure →

The most striking line in the 13 July 2026 joint advisory is not about a novel exploit. It is that a state intelligence service, with more than a decade of practice, keeps succeeding by scanning the open internet for routers still protected by default or weak passwords. The tradecraft is patient; the entry point is negligence. That combination is precisely what governance is supposed to close, and precisely what it keeps leaving open.

What the advisory says

The NSA, FBI and CISA, alongside agencies from a dozen partner countries — Australia’s ASD among them, with the UK, Canada, New Zealand and several European states — issued a joint advisory titled, plainly, Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting. It attributes the activity to FSB Center 16, a signals-intelligence and cyber unit tracked across the industry under a menagerie of names: Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard and Static Tundra.

The targeting is not opportunistic noise. It concentrates on the sectors that keep a country running: communications, the defence industrial base, energy, financial services, government facilities and healthcare. Center 16 has been working these targets for more than ten years.

The uncomfortable part Sophisticated adversaries keep exploiting basic weaknesses for one reason: the basic weaknesses are still there.

The same day the advisory landed, the EU and the UK imposed sanctions on Russian intelligence officers, hackers and front companies over a years-long cyber-espionage campaign, and formally attributed the late-2025 attacks on Poland’s energy infrastructure to Center 16 — an attack the UK stated could have affected half a million citizens had it succeeded. The advisory and the sanctions are two halves of one message: attribution plus consequence.

The attack path — and how ordinary it is

Strip the campaign to its mechanics and it reads like a penetration-testing checklist the defender failed. The adversary scans the internet for exposed network devices, finds ones running weak or default SNMP credentials or unpatched firmware, and turns a perimeter router into a foothold — then moves laterally into the network it guards.

FSB Center 16 router attack path: internet scan, weak SNMP credentials, perimeter foothold, lateral movement into critical infrastructureAttack path: internet-wide scanning of exposed routers with weak SNMP credentials, foothold on the perimeter device, then lateral movement into critical-infrastructure networks. FSB Center 16 · typical intrusion path 01 · Reconnaissance Internet-wide scan Hunt for default / weak SNMP strings 02 · Exposed device Perimeter router Unpatched or misconfigured 03 · Foothold ! Device compromised Persistent access at the network edge 04 · Impact CI Lateral move Into energy, comms, gov, health networks Every stage turns on a control that is standard practice and routinely skipped: default SNMP strings never changed · SNMPv2 instead of authenticated SNMPv3 · unpatched firmware · flat networks with no segmentation.
Figure 1. The intrusion path is a governance failure at every node. None of the four stages requires a zero-day; each requires only that a documented, unglamorous control was not applied and not verified.

Analysts reviewing the campaign made the point bluntly: legacy operational-technology environments still lean on default credentials, exposed management interfaces and flat network architectures. The advisory also notes Center 16’s techniques overlap with those of other state actors, including China-linked groups — so the same weak router is a shared doorway for multiple adversaries, not a Russia-specific problem.

Why this belongs on the Australian agenda

The ASD did not merely receive this advisory — it co-authored it. That matters for accountability. The same themes run through ASD’s own recent Cyber Threat Reporting, which named replacing legacy IT, managing third-party risk and improving logging among its priority moves for national resilience. Router hygiene is where those abstractions become a specific, testable task.

For any organisation captured by the Security of Critical Infrastructure (SOCI) Act, an exposed, unpatched perimeter device is not just a technical finding — it is a gap against a positive security obligation. For APRA-regulated entities, CPS 234 makes the same device a control deficiency against the requirement to secure information assets by criticality. And nearly every mitigation the advisory recommends maps directly onto the Essential Eight: patch applications and operating systems, and restrict administrative privileges.

Prevention — A Board-Verifiable Checklist

  • Inventory every network device. Routers, switches, firewalls — you cannot secure or patch what you have not counted. This is SOCI asset-register discipline applied to the perimeter.
  • Kill default and weak SNMP community strings. Move to SNMPv3 with authentication and encryption. Default strings are the single most-used doorway in this campaign.
  • Patch firmware on a governed cadence. Unpatched, internet-exposed devices are the recurring root cause. Tie this to Essential Eight patching maturity and evidence it.
  • Retire insecure protocols. Disable TFTP where possible; replace it with SCP or SFTP. Close exposed management interfaces to the internet entirely.
  • Segment the network. Use identity-based micro-segmentation so a compromised edge device cannot become free lateral movement into OT and critical systems.
  • Log and monitor the edge. Device-level logging turns a silent foothold into a detectable event — aligned with ASD’s logging priority.

None of this is novel, and that is exactly why it is a governance story, not a technology story. The adversary is betting these controls exist on paper and not in the config. The organisations that close the campaign are the ones that can produce evidence — a current device inventory, an SNMPv3 rollout record, a patch cadence with dates — rather than an intention. That evidence gap is where an external exposure assessment earns its place: it shows a Board what an FSB scanner already sees.

Sources & references

Is Your Vendor Stack
Assessed and Documented?

A BlackFlag Advisory vendor risk assessment gives your Board an independent, evidenced view of what your third-party providers expose — before an incident makes it an urgent question.

Request an Assessment →
Passive Only — No Systems Accessed

All BlackFlag Advisory assessments use exclusively passive OSINT techniques and publicly available data sources. No systems, networks, or accounts are accessed, probed, or tested at any time. Board-ready output delivered within three to seven business days.