CISA/ACSC Joint Advisory โ Russian State-Sponsored Targeting of Network Devices
CISA, the Australian Cyber Security Centre (ASD's ACSC), and international partners released a joint advisory detailing persistent Russian state-sponsored targeting of routers, firewalls, and other network devices.
Details
- Advisory ID: Aa26 194A (CISA)
- Date: July 14, 2026
- Partners: CISA, ACSC (ASD), and other international cybersecurity authorities
- Target: Routers, firewalls, VPN gateways, and other network infrastructure devices
- Source: CISA / ACSC (raw/digests/Cyber-Digest-2026-07-18)
TTPs Observed
The advisory provides observed tactics, techniques, and procedures (TTPs) including: - Credential harvesting from network device management interfaces - Exploitation of unpatched vulnerabilities in router/firewall firmware - Use of compromised network devices as persistent access points - Recommends improved router hygiene as a primary mitigation
Australian Significance
The advisory was co-published on cyber.gov.au, making it directly applicable to Australian organisations. Acsc recommends: - Hardening router and firewall configurations - Ensuring all network device firmware is up to date - Implementing multi-factor authentication on all administrative interfaces - Monitoring for indicators of compromise listed in Aa26 194A
Related Pages
- Acsc Cms Exploitation โ ACSC alert on CMS campaign (same period)
- Fortibleed โ Fortinet credential exposure (related network device compromise)
- Sandworm โ Russian APT with active CAPTCHA-based social engineering