The UK’s National Cyber Security Centre (NCSC) has issued a new advisory urging organisations to review the security of their network infrastructure following evidence of ongoing attacks by a Russian state-backed threat group targeting vulnerable routers and network devices worldwide. The warning was published jointly with 18 international cyber security agencies, highlighting the global scale of the threat.
The advisory attributes the activity to Centre 16, a cyber unit linked to Russia’s Federal Security Service (FSB). Rather than relying on sophisticated zero-day exploits, the group is exploiting organisations that have left internet-facing network devices exposed, misconfigured or running outdated software. Their activity has targeted critical sectors including energy, healthcare, communications, defence and financial services.
Why this matters
While the advisory focuses on critical national infrastructure, the recommendations apply to organisations of all sizes.
Attackers continue to succeed by exploiting common weaknesses such as:
- Weak or default passwords
- Outdated firmware and software
- Poorly configured routers and switches
- Exposed management interfaces
- Legacy network management protocols
These weaknesses can provide attackers with an initial foothold inside a network, allowing them to move laterally, steal sensitive information and establish long-term access before any malicious activity is detected.
The NCSC’s recommendations
The NCSC advises organisations to strengthen the security of internet-facing network infrastructure by:
- Upgrading to secure management protocols such as SNMPv3
- Removing default credentials and enforcing strong authentication
- Applying security updates and firmware patches promptly
- Restricting administrative access to trusted users and networks
- Reviewing firewall rules and exposed management services
- Following recognised cyber security frameworks such as Cyber Essentials and the Cyber Assessment Framework where appropriate.
Prevention starts with visibility
The latest advisory reinforces an important message: many successful cyber attacks do not begin with advanced malware. They begin with an overlooked device, an outdated configuration or an exposed service that provides attackers with an easy way into the network.
Regular vulnerability assessments, proactive monitoring and ongoing network reviews remain some of the most effective ways to reduce this risk before it becomes a security incident.
Unsure how secure your network is?
If you’re unsure whether your firewalls, routers or wider network infrastructure are securely configured, now is a good time to review your environment.
At Zensec, we help organisations identify vulnerabilities, assess external exposure and strengthen their network security through expert security assessments, vulnerability management and managed detection and response services.
If you’d like confidence that your network is protected against today’s evolving threats, get in touch with our team to arrange a security review and discuss how we can help improve your cyber resilience.
Source: National Cyber Security Centre – UK and Allies urge critical sectors to improve defences against Russian intelligence targeting. Read the full NCSC advisory







