[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fp1-gpypx4w6sXJtOavmvi1L0BUQnAckohOgXeghDamA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"afc954e6-dc1d-44de-9644-8bffec5347f4","russian-apt28-exploits-soho-router-vulnerabilities-for-global-dns-hijacking-campaign","ea04173f-8089-4c73-a756-c4186cac05e5","Russian APT28 Exploits SOHO Router Vulnerabilities for Global DNS Hijacking Campaign","Russian threat actors successfully compromised thousands of small office\u002Fhome office (SOHO) routers by exploiting CVE-2023-50224, then modified DNS and DHCP settings to intercept and redirect network traffic. This attack demonstrates how unpatched network infrastructure devices can become powerful espionage tools, allowing attackers to harvest credentials and sensitive data from over 200 organizations and 5,000 consumer devices globally. The widespread nature of this campaign highlights the critical importance of securing and maintaining network appliances that often go overlooked in security programs. Organizations must treat routers and other network devices as critical assets requiring the same security attention as servers and workstations.","**Immediate actions:**\n- Update all SOHO routers and network appliances to the latest firmware versions\n- Change default administrative credentials on all network devices\n- Verify DNS server settings match organizational security policies\n\n**Long-term improvements:**\n- Implement automated vulnerability scanning for all network infrastructure devices\n- Establish a comprehensive asset inventory including all routers, switches, and IoT devices\n- Deploy network monitoring to detect unauthorized DNS configuration changes\n\n**Detection measures:**\n- Monitor DNS query patterns for suspicious redirections or unexpected responses\n- Set up alerts for configuration changes on critical network infrastructure\n- Regularly audit network device configurations against security baselines",[12,13,14,15,16,17],"CIS Control 7","CIS Control 12","NIST CM-2","NIST SI-2","NIST CM-8","NIST CM-3","published","2026-04-08T13:09:01.411491+00:00","2026-04-08T13:09:01.085+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fwww.securityweek.com\u002Fus-disrupts-russian-espionage-operation-involving-hacked-routers-and-dns-hijacking\u002F","us-disrupts-russian-espionage-operation-involving-hacked-routers-and-dns-hijacki","US Disrupts Russian Espionage Operation Involving Hacked Routers and DNS Hijacking",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":33,"name":34,"slug":35,"description":36,"color":37},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[39],{"id":40,"date":41,"edition":42,"title":43,"audio_url":44},"50df281a-961d-4aca-a22d-7fd7c5a8d3c1","2026-04-08","afternoon","ThreatNoir Afternoon Brief — April 8","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-04-08\u002Fthreatnoir-afternoon-brief-2026-04-08.mp3"]