The National Cyber Security Centre warns that Russian actor APT28 is exploiting vulnerable routers, highlighting how traditional perimeter-based security models are failing to protect modern, distributed enterprise networks.
Key Points
- The NCSC issued an advisory regarding Russian cyber actor APT28 using DNS hijacking to exploit vulnerabilities in enterprise routers.
- State-sponsored actors, including those linked to Volt Typhoon, previously compromised over 100 US utility companies by exploiting unpatched FortiGate 300D firewalls.
- Verizon’s 2025 Data Breach Investigations Report identifies the human element and credential theft as factors in 60% of all security breaches.
- Experts recommend out-of-band management (OOBM) to maintain visibility and control of edge devices via a secure, parallel network path during cyber incidents.
- Modern threats are increasingly augmented by agentic AI tools, which allow attackers to move laterally through systems in minutes after gaining initial access.