APT28 exploit routers to enable DNS hijacking operations
2026-04-08T20:52:19Z•d70cf5fa3583e592a99a707a17c58e6c90c2c87491ca85ee5ebd39bf1f35e834
apt28big-ip apmcisco catalyst sd-wancitrix netscalercredential theftcspmcyber guidancedns hijackingdoseasmedge devicesf5 big-ipfrontier aihacktivistmessaging app targetingmiddle east conflict advisorymitmncscnetscaler adcnetscaler gatewayrcerouterssd-wan compromisevulnerability management
What happened
UK NCSC alerts (Jan–Apr 2026) covering multiple active and high-impact threats: Russian APT28 is exploiting vulnerable edge routers to perform DNS hijacking (enabling MitM, credential and token theft); agencies report active exploitation/compromise of Cisco Catalyst SD‑WAN; an unauthenticated remote‑code‑execution vulnerability affects F5 BIG‑IP APM (NCSC urges mitigation); and two recently disclosed vulnerabilities affect Citrix NetScaler ADC and Gateway (immediate action recommended). Additional guidance/alerts include messaging‑app targeted‑attack mitigations, warnings about pro‑Russia hack
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- uk_ncsc_all_rss
- Record identifier
- d70cf5fa3583e592a99a707a17c58e6c90c2c87491ca85ee5ebd39bf1f35e834
- Enrichment time
- 2026-04-08T20:52:19Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.