Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
CISA Warns Russian FSB Hackers Are Hijacking Home and Small Office Routers

The federal government has a blunt message for anyone running a home or small office router: lock it down, because Russian state hackers are actively hunting for it.
On Monday, the Cybersecurity and Infrastructure Security Agency, along with counterpart agencies in Australia, Denmark, New Zealand, and the UK, issued a joint advisory naming the culprit directly. "Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks," CISA said.
This isn't a new group. The hacking unit goes by several names in the security industry, including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra, according to CISA. Different vendors track the same crew under different labels, but the target list is consistent: communications, defense, energy, financial services, and government networks.
How the routers get hijacked
The method is not exotic. According to CISA, the hackers scan IP ranges looking for routers running Simple Network Management Protocol agents that still accept common or default login credentials. SNMP is a legitimate tool used to manage networking gear remotely, but versions 1 and 2 don't encrypt passwords or follow other basic security practices, per the advisory.
Once the hackers get in, they don't necessarily do anything to the router owner directly. Instead, they turn the compromised device into an exit node. Traffic aimed at real targets gets funneled through your router first, so it looks like it's coming from a trustworthy home IP address instead of a known attacker. That makes it harder for firewalls and security teams at the actual targets to block the traffic.
It's a laundering operation for internet traffic. Your router is the washing machine.
This has been going on for years, and it's not just Russia
Russian and Chinese state hackers have both been compromising routers for years, according to Ars Technica, sometimes fighting each other for control of devices one side already hijacked. The US government has occasionally issued its own covert countermeasures to disinfect routers, and companies including Google have worked to disrupt the botnets tying these devices together.
None of it has solved the problem permanently. The pattern is whack-a-mole: authorities take down a botnet, and the same operators rebuild with new compromised devices.
One notable gap in Monday's advisory: it says nothing about identical operations that Chinese state-linked groups have run in recent years. China's hacking operations against similar infrastructure have been well documented, and residential proxy networks built from hijacked devices are also a favorite tool of financially motivated criminal hackers, not just Kremlin-linked ones. Whether CISA left China out of this specific advisory because the current investigation is Russia-specific, or for other reasons, isn't explained in the agency's release.
CISA is naming a specific, well-documented threat actor group and a specific technical method. This is not a vague warning about hacking in general. But the advisory doesn't name individual victim organizations or specify how many routers have been compromised, so the scale of the current campaign remains unclear from what's public.
What CISA wants people to actually do
The agency's core recommendation is simple: disable SNMP versions 1 and 2 entirely. If SNMP is needed at all, only version 3 should be used, since it actually encrypts credentials. Better yet, CISA suggests disabling SNMP access altogether if you don't need remote management of your device.
For the average person, that means logging into your router's admin settings, which most people have never touched since the day they installed it, and checking whether SNMP is even enabled. Most consumer routers ship with it off by default, but small offices and users who've customized their setups are more exposed.
The deeper issue is one security researchers have flagged for years: millions of routers sit on home networks running outdated firmware with factory-default logins, and nobody is patching them. That's not a Russia problem or a China problem specifically. It's an incentive problem. Router manufacturers face little pressure to push automatic security updates, and most consumers have no idea their device is even a target.
CISA's advisory doesn't include a deadline or penalty for noncompliance because there isn't one. Router security remains voluntary, and until that changes, agencies will keep issuing warnings after the fact rather than closing the gap before the next FSB scan finds an open door.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.