Washington D.C. & London – July 13-14, 2026 – Cybersecurity agencies from the United States and its international partners have issued urgent advisories warning of ongoing state-sponsored cyberattacks by Russian intelligence operatives targeting critical infrastructure sectors globally. The National Security Agency (NSA), Federal Bureau of Investigation (FBI), and Cybersecurity and Infrastructure Security Agency (CISA) in the U.S., alongside UK and other international partners, revealed that Russian-linked hackers are exploiting vulnerable and misconfigured networking devices, particularly routers, to gain persistent access to sensitive networks.

The joint advisories, released on July 13-14, 2026, highlight that threat actors associated with Russian intelligence, specifically identified as elements of the Russian Federal Security Service Section 16 (tracked as Berzerk Bear or Dragonfly), are leveraging poorly secured internet-facing devices. Instead of relying on novel zero-day exploits, these groups are capitalizing on common weaknesses such as weak or default Simple Network Management Protocol (SNMP) community strings, known vulnerabilities in Cisco equipment (including its Smart Install feature), and exposed web management portals.

Once a foothold is established, these operatives are able to conduct extensive reconnaissance, collect credentials, monitor network traffic, and expand their access within the targeted networks. The critical infrastructure sectors at risk include energy, communications, healthcare, industrial control systems, finance, and defense. The aim of these long-term campaigns appears to be espionage and preparation for potential disruptive activities.

The warnings underscore a concerning trend where advanced persistent threat (APT) groups, even state-backed ones, are frequently exploiting basic security hygiene failures rather than solely sophisticated attacks. For instance, Cisco networking devices have historically been a frequent target due to their pervasive use and potential for deep system access.

Impact on Global Cybersecurity

The ongoing exploitation poses significant risks, particularly to organizations that manage critical services. Successful breaches could lead to data exfiltration, service disruptions, or even destructive attacks on essential utilities. The revelation that these attacks often stem from unpatched systems or weak configurations serves as a stark reminder for organizations to maintain rigorous cybersecurity practices. The urgency of these warnings is amplified by previous incidents, such as an alleged Russian attack on Poland's energy grid, which, despite failing, underscored the potential for widespread power loss impacting 500,000 people.

How to Protect Your Organization

Cybersecurity agencies have provided clear recommendations to mitigate the risks associated with these attacks:

This collaborative international warning highlights the persistent and evolving threat landscape, emphasizing the need for proactive defense measures and robust cyber hygiene across all sectors, particularly those deemed critical.