Cybersecurity: “The Russians are Coming! The Russians are Coming!” (Again)

by John Jenkins

July 22, 2026

This Robinson + Cole blog highlights a recent cybersecurity advisory from the United States and 12 other nations indicating that Russian state-sponsored hackers have been exploiting poorly configured network devices, primarily routers, to break into systems. This excerpt from the blog has more details:

The threat group, also known as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard and Static Tundra, has been scanning the internet for routers with default or weak passwords, or unpatched old Cisco vulnerabilities.

The agencies “strongly urge device owners and network defenders to take mitigation and remediation actions against Russian government-sponsored exploitation of vulnerable routers.”

The industries that have been targeted include: “communications, defense industrial base, energy, financial services, government services and facilities, especially organizations at the state and local level, and healthcare and public health.” The advisory provides details of techniques used, and mitigation actions to deploy. Tracking these techniques and applying the mitigation actions should be a priority for critical infrastructure organizations.

As this excerpt from a 2022 Congressional Research Service report indicates, this is just the latest chapter in a long-running series of Russian state-sponsored cyber-attacks.