The federal government is warning users of home and small office routers to secure their devices as Russia state hackers continue to mass-compromise them for use in obscuring nefarious actions against sensitive organizations in the public and private sectors.
Both the Russian and Chinese governments have been compromising routers for years, sometimes in prolonged tugs-of-war to wrest control of devices the other has already commandeered. The US government has occasionally issued covert commands and taken other steps to disinfect routers. Google and other companies have also worked to disrupt the massive botnets that control compromised routers in lockstep. The actions to date are little more than whack-a-mole exercises as the operators simply replace their botnets with new ones.
Proxy networks: The go-to tool
“Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks,” the Cybersecurity and Infrastructure Security Agency said Monday. The hacking groups are tracked under various names, including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra. The advisory was co-issued by governments from around the world, including Australia, Denmark, New Zealand, and the UK.Read full article
Comments
OpenAI推出‘Trusted Access for Cyber program’,通过向可信网络安全防御者提供先进AI模型,加速漏洞检测与修补进程。该计划旨在应对当前漏洞修补响应迟缓的痛点,利用AI技术提升分析效率,缩短安全风险窗口。行业分析认为,此举推动AI增强防御范式,促进协同安全,但也面临模型可靠性及企业接受度等挑战。未来有望激发创新,助力构建更安全的数字基础设施。