Western agencies warn of russian hackers on tp-link routers

The FBI, BND and BfV warn of attacks by Russian state hackers on TP-Link routers and WLAN extenders. The Fancy Bear group has infiltrated thousands of devices worldwide to steal sensitive data. In Germany, 30 affected devices have already been detected.

International agencies including the FBI, NSA, BND and BfV issued a joint warning on Monday evening. They attribute the attacks to the Fancy Bear group, also known as APT 28, linked to Russia's GRU military intelligence. The hacks target military, government and critical infrastructure data.

Since mid-March, German IT firms, restaurants and private individuals received confidential letters from the BfV. It stated: "A Russian state cyber actor is currently compromising TP-Link network devices." Affected parties were instructed on detecting and fixing infections. In Germany, experts confirmed compromises and are forensically examining devices.

Hackers have exploited a known vulnerability in TP-Link devices since 2024, fixable via firmware updates. Using DNS hijacking, they redirect web requests to controlled servers to steal passwords, emails and browsing histories. The UK's National Cyber Security Centre also reports attacks on MikroTik routers.

The BfV plans to act against APT 28. TP-Link, originally Chinese, faces scrutiny: Texas sued in February, and the US FCC recently banned imports for security reasons.

相关文章

Netgear and Eero Wi-Fi routers displayed with an FCC exemption document in a professional office setting.
AI 生成的图像

Netgear and Eero gain exemptions from FCC foreign router ban

由 AI 报道 AI 生成的图像

The Federal Communications Commission has granted exemptions to Netgear and Eero from its ban on new foreign-made Wi-Fi routers. The move follows the original March 23 order that targeted devices with manufacturing or design outside the United States. Firmware updates for existing models will continue until at least January 1, 2029.

US federal agencies have disclosed that Russian military intelligence compromised thousands of small office and home routers, urging owners to take immediate protective measures.

由 AI 报道

Researchers have uncovered a large-scale compromise of Fortinet firewalls that exposed plaintext credentials for nearly 74,000 devices across 194 countries. The breach affects organizations including Oracle, Chevron, Lenovo, FedEx, and Fortinet itself, along with a NATO defense contractor.

此网站使用 cookie

我们使用 cookie 进行分析以改进我们的网站。阅读我们的 隐私政策 以获取更多信息。
拒绝