A Decade-Old Bug Still Haunts America’s Smallest Agencies

An overlooked Cisco flaw, long patched but still lingering on outdated equipment, has become a doorway for Russian hackers. Federal officials say the weakest points in the nation’s digital defenses lie with the small utilities and local networks that can least afford to secure them.

When the FBI issued a public warning in August about Russian hackers abusing a long-known flaw in Cisco devices, the message wasn’t aimed at Wall Street or big tech. It was meant for the kinds of organizations most people rarely notice—local utilities and regional authorities that keep everyday services running and often operate with thin budgets and aging gear. On the same day, Cisco’s threat-intelligence team published technical details that underscored the risk.

The campaign is attributed to a Russian state-sponsored group that security researchers call Static Tundra, which they link to the F.S.B.’s Center 16 unit and to the broader cluster known as Energetic/Berserk Bear. According to US officials and Cisco researchers, the group has spent more than a decade compromising network devices as a beachhead for long-term espionage.

At the center is CVE-2018-0171, a vulnerability in Cisco’s Smart Install feature. Left unpatched, it exposes devices listening on TCP port 4786 and can allow attackers to crash equipment, seize control, or plant code that persists across reboots. Many victims, investigators say, are running end-of-life hardware that never received updates.

The FBI says the actors have recently collected configuration files from thousands of US networking devices tied to critical infrastructure, in some cases modifying settings to enable unauthorized access and reconnaissance. Cisco reports similar activity worldwide, with particular focus on Ukraine and allied countries since the war began.

While the current wave is aimed at data collection and access, the tradecraft echoes earlier router compromises. Investigators have tied the group to historic use of “SYNful Knock,” a stealthy firmware implant first documented in 2015 that gives attackers durable control over Cisco routers.

US agencies and Cisco urge organizations to take basic but often under-resourced steps: apply patches or disable Smart Install, implement phishing-resistant multifactor authentication, segment networks so a single failure doesn’t cascade, and audit internet-facing devices for unexpected changes. For small public agencies with limited staff, those measures can be difficult to sustain—yet they remain the strongest defense.

For corrections, news tips, and any other content requests, please send us an email at [email protected].

Hot this week

Curiosity and Creativity Collide at GEAR UP STEM Conference 

The annual GEAR UP New Mexico and STEM Santa Fe Pathways Conference inspired students through hands-on STEM learning experiences.

Trump Administration Scraps ‘Public Lands Rule,’ Opening Millions of Acres to New Drilling and Mining

The Trump administration has formally repealed the Biden-era Public Lands Rule, ending a policy that required conservation to be weighed equally with drilling, mining and grazing on federal lands. Environmental groups warn the move could accelerate industrial development across millions of acres in the American West.

Former Albuquerque Teacher Found Guilty in Sexual Violation

Patrick Corr, former teacher at John Adams Middle School has been found guilty for sexually abusing his student.

Police Are Learning to Hear You—And It’s a Game-Changer

A new investigative interviewing course at the New Mexico Law Enforcement Academy is teaching officers to replace coercive interrogations with science-based conversations focused on truth, trust and accurate information gathering.

Anchorum Health Foundation Strengthens Native Nation Building in New Mexico

The Anchorum Health Foundation (the Foundation) provides leadership and support for advancing Indigenous nation building and improving the social determinants of health of Indigenous people living in New Mexico through its work with Indigenous-led organisations by moving from focusing on building partnerships with hospitals toward focusing on creating partnerships within the local communities. The Foundation will partner with Indigenous-led organisations to support funding for housing, assist with navigating Tribal laws, and assist in preserving and sharing indigenous knowledge systems. These efforts by the Foundation will build the ability of Tribes to self-govern, establish greater trust between the community and the provider, and create general equalities in housing and health care as well as overall well-being within the community.

Topics

Curiosity and Creativity Collide at GEAR UP STEM Conference 

The annual GEAR UP New Mexico and STEM Santa Fe Pathways Conference inspired students through hands-on STEM learning experiences.

Trump Administration Scraps ‘Public Lands Rule,’ Opening Millions of Acres to New Drilling and Mining

The Trump administration has formally repealed the Biden-era Public Lands Rule, ending a policy that required conservation to be weighed equally with drilling, mining and grazing on federal lands. Environmental groups warn the move could accelerate industrial development across millions of acres in the American West.

Former Albuquerque Teacher Found Guilty in Sexual Violation

Patrick Corr, former teacher at John Adams Middle School has been found guilty for sexually abusing his student.

Police Are Learning to Hear You—And It’s a Game-Changer

A new investigative interviewing course at the New Mexico Law Enforcement Academy is teaching officers to replace coercive interrogations with science-based conversations focused on truth, trust and accurate information gathering.

Anchorum Health Foundation Strengthens Native Nation Building in New Mexico

The Anchorum Health Foundation (the Foundation) provides leadership and support for advancing Indigenous nation building and improving the social determinants of health of Indigenous people living in New Mexico through its work with Indigenous-led organisations by moving from focusing on building partnerships with hospitals toward focusing on creating partnerships within the local communities. The Foundation will partner with Indigenous-led organisations to support funding for housing, assist with navigating Tribal laws, and assist in preserving and sharing indigenous knowledge systems. These efforts by the Foundation will build the ability of Tribes to self-govern, establish greater trust between the community and the provider, and create general equalities in housing and health care as well as overall well-being within the community.

Health Officials Calm Fears After Cruise Ship Hantavirus Outbreak

New Mexico health officials moved quickly to calm fears after reports of a cruise ship hantavirus outbreak abroad. They emphasized that the local Sin Nombre strain does not spread person‑to‑person, unlike the Andes strain linked to the ship. Officials urged residents to follow prevention guidelines — wearing masks and gloves when cleaning rodent areas and disinfecting droppings with bleach — to reduce risk. They confirmed that no New Mexicans were aboard the ship and only one local case has been reported in 2026. By clarifying the difference between strains and reinforcing safe practices, officials reassured the public and prevented unnecessary alarm while keeping awareness high.

Attention Job Seekers: APS to Hold College & Career Fair on May 23

If you’re job hunting, this is your chance to connect with top employers.

New Mexico’s Universal Childcare Program is Costing More Than Expected — and the Bills Are Already Piling Up

New Mexico’s ambitious universal childcare expansion is drawing thousands of new families into the system — but unexpected enrollment growth is straining state budgets and raising concerns about the long-term sustainability of one of the nation’s most closely watched early childhood initiatives.

Related Articles