Agencies in the U.S. and United Kingdom this week released an advisory detailing tactics used to exploit a known vulnerability in Cisco routers to deploy malware and recommendations to protect vulnerable Cisco devices. 

“This joint U.S. and U.K. advisory cites with high confidence that elements of the Russian Military Intelligence Service have been exploiting a known vulnerability in Cisco network routers since at least 2017,” said John Riggi, AHA’s national advisor for cybersecurity and risk. “Like the SolarWinds compromise, this highlights the ongoing targeting of strategic third-party network technology, which is widely present in government and private-sector networks. These strategic cyberattacks on the technology supply chain may give the Russian government a basis to conduct covert reconnaissance of sensitive networks, steal data and/or pre-position itself for future destructive cyberattacks. It is strongly recommended that the patch for vulnerability CVE-2017-6742 be implemented as soon as possible.”

For more information on this or other cyber and risk issues, contact Riggi at jriggi@aha.org. For the latest cyber and risk resources and threat intelligence, visit aha.org/cybersecurity.

Related News Articles

Perspective
When hospitals are attacked, lives are threatened. This is the reality our entire field faces every day. But the never-ending barrage of ransomware and…
Headline
The FBI, National Security Agency and Cyber National Mission Force last week issued a joint advisory about recent actions of China-linked cyber actors…
Headline
The Health Information Sharing and Analysis Center last week announced that Veeam, a software company that provides data protection, backup and disaster…
Headline
The Cybersecurity and Infrastructure Security Agency Aug. 21 published guidance providing best practices for event logging to mitigate cyberthreats. The…
Headline
The AHA has released five new tip sheets designed to fortify crisis leadership competencies during emergency events such as cyberattacks, natural disasters and…
Headline
The FBI, Cybersecurity and Infrastructure Agency and the Department of Defense Cyber Crime Center Aug. 29 issued a joint advisory to warn of Iranian-based…