Agencies in the U.S. and United Kingdom this week released an advisory detailing tactics used to exploit a known vulnerability in Cisco routers to deploy malware and recommendations to protect vulnerable Cisco devices. 

“This joint U.S. and U.K. advisory cites with high confidence that elements of the Russian Military Intelligence Service have been exploiting a known vulnerability in Cisco network routers since at least 2017,” said John Riggi, AHA’s national advisor for cybersecurity and risk. “Like the SolarWinds compromise, this highlights the ongoing targeting of strategic third-party network technology, which is widely present in government and private-sector networks. These strategic cyberattacks on the technology supply chain may give the Russian government a basis to conduct covert reconnaissance of sensitive networks, steal data and/or pre-position itself for future destructive cyberattacks. It is strongly recommended that the patch for vulnerability CVE-2017-6742 be implemented as soon as possible.”

For more information on this or other cyber and risk issues, contact Riggi at jriggi@aha.org. For the latest cyber and risk resources and threat intelligence, visit aha.org/cybersecurity.

Related News Articles

Headline
New guidance released yesterday by the Cybersecurity and Infrastructure Security Agency, National Security Agency and FBI informs health care and other…
Headline
A joint advisory released Nov. 20 by the Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency and international partners warns of…
Headline
The Department of Justice Nov. 18 announced criminal charges against Evgenii Ptitsyn, a Russian national, for allegedly administering the sale, distribution…
Headline
A United Nations Security Council meeting the week of Nov. 4 discussed ransomware and the severe impacts that cyberattacks can have on hospitals and health…
Headline
AHA President and CEO Rick Pollack was recently a guest on Pinkston's "To the Point" podcast to discuss the future of U.S. health care, touching on a range of…
Headline
The Cybersecurity and Infrastructure Security Agency, FBI and other federal agencies have created a webpage with the latest cyberthreat updates and information…