Shanaka Anslem Perera ⚡[verified]@shanaka86Active Exploitation
The post highlights severe vulnerabilities being actively exploited via a kernel‑level rootkit that persists through reboots and patches, underscoring that hardware replacement is only effective way to eradicate the threat.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
Russian FSB Center 16 is actively exploiting CVE‑2018‑0171 on routers using SNMP default credentials to exfiltrate configuration files via TFTP.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
FSB Center 16 leveraged CVE‑2018‑0171 to compromise routers in defense, energy, and healthcare sectors, mapping internal networks and establishing persistent C2 channels for data exfiltration.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
Russian FSB actors actively exploited default SNMP credentials and CVE-2018-0171 on critical infrastructure routers, using the compromised devices to pivot and move laterally across networks.
Rıdvan Yağlı[verified]@ridvanyagliActive Exploitation
NSA warns that Russian attackers are actively exploiting CVE‑2018‑0171 on Cisco routers and switches via Smart Install, urging users to disable the feature and apply patches.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
The post reports that FSB operatives are exploiting CVE‑2018‑0171 and default SNMP credentials to hijack critical infrastructure routers, moving laterally and exfiltrating config files via TFTP, while suggesting runtime segmentation as a mitigation.
TECHEPAGES[verified]@techepagesActive Exploitation
The post reports that Russia's FSB is actively exploiting CVE‑2018‑0171 in critical infrastructure, while noting the patch/mitigation steps of SNMPv3 and blocking TFTP/SMI.
CISA Cyber@CISACyberGeneral
The advisory outlines tactics used by Russian actors targeting Cisco routers via CVE-2018-0171 and CVE-2008-4128, but it does not provide PoC, exploit code, patch info, or evidence of active exploitation.