A Decade-Old Bug Still Haunts America’s Smallest Agencies

An overlooked Cisco flaw, long patched but still lingering on outdated equipment, has become a doorway for Russian hackers. Federal officials say the weakest points in the nation’s digital defenses lie with the small utilities and local networks that can least afford to secure them.

When the FBI issued a public warning in August about Russian hackers abusing a long-known flaw in Cisco devices, the message wasn’t aimed at Wall Street or big tech. It was meant for the kinds of organizations most people rarely notice—local utilities and regional authorities that keep everyday services running and often operate with thin budgets and aging gear. On the same day, Cisco’s threat-intelligence team published technical details that underscored the risk.

The campaign is attributed to a Russian state-sponsored group that security researchers call Static Tundra, which they link to the F.S.B.’s Center 16 unit and to the broader cluster known as Energetic/Berserk Bear. According to US officials and Cisco researchers, the group has spent more than a decade compromising network devices as a beachhead for long-term espionage.

At the center is CVE-2018-0171, a vulnerability in Cisco’s Smart Install feature. Left unpatched, it exposes devices listening on TCP port 4786 and can allow attackers to crash equipment, seize control, or plant code that persists across reboots. Many victims, investigators say, are running end-of-life hardware that never received updates.

The FBI says the actors have recently collected configuration files from thousands of US networking devices tied to critical infrastructure, in some cases modifying settings to enable unauthorized access and reconnaissance. Cisco reports similar activity worldwide, with particular focus on Ukraine and allied countries since the war began.

While the current wave is aimed at data collection and access, the tradecraft echoes earlier router compromises. Investigators have tied the group to historic use of “SYNful Knock,” a stealthy firmware implant first documented in 2015 that gives attackers durable control over Cisco routers.

US agencies and Cisco urge organizations to take basic but often under-resourced steps: apply patches or disable Smart Install, implement phishing-resistant multifactor authentication, segment networks so a single failure doesn’t cascade, and audit internet-facing devices for unexpected changes. For small public agencies with limited staff, those measures can be difficult to sustain—yet they remain the strongest defense.

For corrections, news tips, and any other content requests, please send us an email at [email protected].

Hot this week

Gas Prices Remain High Despite Summer Season Fast Approaching

Gas prices will remain high despite the approaching summer season.

Tau Herculids Meteor Shower That Could Surprise Everyone Peaks Tonight — And New Mexico May Have Front-Row Seats

New Mexico’s renowned dark skies could become the stage for the Tau Herculids meteor shower on the night of May 30 to May 31. Known for its unpredictable nature, this celestial event—born from the shattered fragments of comet 73P/Schwassmann–Wachmann 3—may deliver anything from a quiet show to a surprise burst of meteors.

Smoking Rates are Falling, Vaping is Rising: Why New Mexico’s Anti-Smoking Victory Comes With a New Public Health Warning

New Mexico has reduced cigarette smoking to its lowest level in years, but rising e-cigarette use reveals a new challenge: nicotine addiction is evolving, not disappearing.

‘Every Role at APS Is Vital’: Superintendent Blakey Honors Staff as School Year Closes

APS Superintendent Gabriella Blakey took the opportunity to express gratitude and appreciation to district staff–from teachers to drivers and cooks–as another school year ends.

Albuquerque Police Release Video of Deadly Shooting Involving a 23-Year-Old Man

APD released a bodycam video regarding the deadly shooting that happened at the victim's home.

Topics

Gas Prices Remain High Despite Summer Season Fast Approaching

Gas prices will remain high despite the approaching summer season.

Tau Herculids Meteor Shower That Could Surprise Everyone Peaks Tonight — And New Mexico May Have Front-Row Seats

New Mexico’s renowned dark skies could become the stage for the Tau Herculids meteor shower on the night of May 30 to May 31. Known for its unpredictable nature, this celestial event—born from the shattered fragments of comet 73P/Schwassmann–Wachmann 3—may deliver anything from a quiet show to a surprise burst of meteors.

Smoking Rates are Falling, Vaping is Rising: Why New Mexico’s Anti-Smoking Victory Comes With a New Public Health Warning

New Mexico has reduced cigarette smoking to its lowest level in years, but rising e-cigarette use reveals a new challenge: nicotine addiction is evolving, not disappearing.

‘Every Role at APS Is Vital’: Superintendent Blakey Honors Staff as School Year Closes

APS Superintendent Gabriella Blakey took the opportunity to express gratitude and appreciation to district staff–from teachers to drivers and cooks–as another school year ends.

Albuquerque Police Release Video of Deadly Shooting Involving a 23-Year-Old Man

APD released a bodycam video regarding the deadly shooting that happened at the victim's home.

Questions Still Remain Over What Really Happened in a Deadly Police Shooting

After a deadly shooting, the family of the victim was frustrated over how the officers handled the case.

Shooting in NW Albuquerque Leaves to 2 Officers, Suspect Dead

A shootout in Northwest Albuquerque has led to the deaths of the 2 officers and the suspect himself.

What New Mexico Farmers and Ranchers Need to Know About Federal Drought Relief

The USDA has declared all 33 New Mexico counties drought disaster areas, giving farmers and ranchers access to emergency loans as severe drought tightens its grip across the state.

Related Articles