惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
WordPress大学
WordPress大学
T
Tailwind CSS Blog
V
Visual Studio Blog
月光博客
月光博客
Hugging Face - Blog
Hugging Face - Blog
小众软件
小众软件
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - Franky
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Last Week in AI
Last Week in AI
阮一峰的网络日志
阮一峰的网络日志
量子位
有赞技术团队
有赞技术团队
酷 壳 – CoolShell
酷 壳 – CoolShell
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
Jina AI
Jina AI
雷峰网
雷峰网
博客园 - 【当耐特】
博客园 - 叶小钗
美团技术团队
宝玉的分享
宝玉的分享
IT之家
IT之家

The Register - Security

India's cyber agency sets clock at 12 hours to tackle exploited bugs as AI turns up the heat Are we human? MyPillow must decide whether to be firm or soft as ransomware crims demand pay Experts pour cold borscht on Farage's Russian hack claim AI eyes scanning for bugs create a worrisome Linux security trend A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Techie claims Trump Mobile website was leaking thousands of people's data Dems slam Trump for making cybersecurity hold out the tin cup while splurging on ballroom and Jan. 6 'slush fund' Attackers spill plaintext passwords of 46k Myspace93 users after 2021 breach Microsoft open-sources agentic AI safety tools Are we human? America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames America's top cyber-defense agency left a GitHub repo open with passwords, keys, tokens – and incredibly obvious filenames Shai-Hulud copycat worm infects yet another npm package MPs want social media treated more like unsafe toys than harmless apps Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data To gain root access, intruder just had to ask AWS patched Quick auth bypass, says customers weren't using control Disgruntled researcher releases two more Microsoft zero-days Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files US bank reports itself after slinging customer data at 'unauthorized AI app' Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator Best Western Hotels confirms web app data breach Arctic Wolf cuts 250 jobs in AI push 1 in 8 workers say selling company logins is justifiable Iran cyberspies LARPing as ransomware crims in espionage ops UK age-gating plans risk breaking the internet, privacy groups warn India orders infosec red alert in case Mythos sparks crime 'CopyFail' attackers start cashing in on Linux flaw
Russia's Fancy Bear still attacking routers to boost fake...
2026-04-08 · via The Register - Security

The UK's National Cyber Security Centre (NCSC) has issued a fresh warning about Russia's ongoing targeting of routers to steal passwords and other secrets.

It said APT28, aka Fancy Bear, a group widely attributed to Russian intelligence (GRU), is exploiting vulnerabilities in small and home office (SOHO) routers and changing their DNS server settings to redirect victims to websites it controls.

In many cases, altering these DNS settings can also cause downstream devices to inherit them, such as laptops and smartphones, exposing them to malicious connections.

Fancy Bear typically reroutes victims searching for commonly visited services such as Outlook to websites under its control. Victims are instead served an Outlook copycat page, into which they unwittingly enter their legitimate credentials to access the service.

TP-Link routers were name-dropped specifically, although Cisco routers were previously caught up in the same activity, which the NCSC has monitored since 2021.

A separate cluster of similar activity targeted MikroTik routers. The NCSC believes many of these were located in Ukraine, and compromising them would allow Russia to gather data with military intelligence value.

Although the DNS hijacking activity has been ongoing for years and was carried out by sophisticated threat actors, the NCSC said it was likely opportunistic rather than singling out high-value individuals for targeting.

Paul Chichester, director of operations at the NCSC, said: "This activity demonstrates how exploited vulnerabilities in widely used network devices can be leveraged by sophisticated hostile actors.

"We strongly encourage organizations and network defenders to familiarise themselves with the techniques described in the advisory and to follow the mitigation advice.

"The NCSC will continue to expose Russian malicious cyber activity and provide practical guidance to help protect UK networks."

Microsoft also published its own report on the attacks, adding that APT28 (Forest Blizzard in Redmond nomenclature) was likely hoping to compromise routers at organizations upstream of large targets.

In doing so, that could give the group access to enterprise environments and a trove of other sensitive data.

It stated: "Microsoft Threat Intelligence has identified over 200 organizations and 5,000 consumer devices impacted by Forest Blizzard's malicious DNS infrastructure; telemetry did not indicate compromise of Microsoft-owned assets or services."

Microsoft went on to say that APT28 could also use successful attacks for other purposes, such as DDoS attacks and deploying malware.

One of the NCSC's earlier advisories, dated April 2023, noted that similar attacks on Cisco routers resulted in APT28 deploying Jaguar Tooth malware, establishing backdoors for follow-on attacks. ®