US and allied Governments’ Recommendations: Securing Network Devices Against Russian APT Groups
2026-07-16T02:51:42Z•fecf762c9eded1b80894030426f9d7e0f0188acc3f28b1a4e4d766b425d66900
621 CVEsAI-generated malwareAPTAsyncAPICISACrashStealerKnown Exploited VulnerabilitiesLegacyHivePatch TuesdayPowerShell reconnaissance','ransomware infrastructure','sanctionProfSvcRussian state-sponsoredSMA 1000SonicWallWindows Privilege Escalationcritical infrastructureinfostealermacOSmalwarenetwork devicesnpmrouterssigned appssupply chainzero-day
What happened
Multiple high-impact cybersecurity developments: US and allied governments warn Russian state-linked APT groups are actively targeting poorly secured routers and network devices to access critical infrastructure. A new Windows Privilege Escalation PoC called LegacyHive (targeting ProfSvc) works against fully patched systems, and Microsoft’s July 2026 Patch Tuesday fixed a record 621 CVEs (including exploited zero-days). Active exploitation was confirmed against SonicWall SMA 1000 appliances (two zero-days), and CISA added SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities (KE
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- fecf762c9eded1b80894030426f9d7e0f0188acc3f28b1a4e4d766b425d66900
- Enrichment time
- 2026-07-16T02:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.