FBI Warns FSB-Linked Hackers Exploiting Unpatched Cisco Devices for Cyber Espionage
A seven-year-old security hole in Cisco IOS and Cisco IOS XE software has been regularly exploited by Static Tundra, a Russian state-sponsored cyber espionage group, to gain continuous access to target networks.
According to Cisco Talos, which made the activity public, the attacks target companies in the manufacturing, telecommunications, and higher education sectors in North America, Asia, Africa, and Europe. According to the statement, recent efforts have been made against Ukraine and its allies since the start of the Russo-Ukrainian war in 2022, and prospective victims are selected based on their "strategic interest" to Russia.
The vulnerability in question is CVE-2018-0171 (CVSS score: 9.8), a serious weakness in Cisco IOS Software and Cisco IOS XE software's Smart Install capab...

