Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-18 ยท updated: 2026-07-18 ยท tags: [nation-state, russia, cisa, acsc, network-infrastructure, joint-advisory] ยท confidence: high ยท affected_sectors: [government, defence, technology, energy] ยท au_impact: true

CISA/ACSC Joint Advisory โ€” Russian State-Sponsored Targeting of Network Devices

CISA, the Australian Cyber Security Centre (ASD's ACSC), and international partners released a joint advisory detailing persistent Russian state-sponsored targeting of routers, firewalls, and other network devices.

Details

  • Advisory ID: Aa26 194A (CISA)
  • Date: July 14, 2026
  • Partners: CISA, ACSC (ASD), and other international cybersecurity authorities
  • Target: Routers, firewalls, VPN gateways, and other network infrastructure devices
  • Source: CISA / ACSC (raw/digests/Cyber-Digest-2026-07-18)

TTPs Observed

The advisory provides observed tactics, techniques, and procedures (TTPs) including: - Credential harvesting from network device management interfaces - Exploitation of unpatched vulnerabilities in router/firewall firmware - Use of compromised network devices as persistent access points - Recommends improved router hygiene as a primary mitigation

Australian Significance

The advisory was co-published on cyber.gov.au, making it directly applicable to Australian organisations. Acsc recommends: - Hardening router and firewall configurations - Ensuring all network device firmware is up to date - Implementing multi-factor authentication on all administrative interfaces - Monitoring for indicators of compromise listed in Aa26 194A

Related Pages

  • Acsc Cms Exploitation โ€” ACSC alert on CMS campaign (same period)
  • Fortibleed โ€” Fortinet credential exposure (related network device compromise)
  • Sandworm โ€” Russian APT with active CAPTCHA-based social engineering