UK exposes Russian military intelligence hijacking vulnerable routers for cyber attacks

2026-04-07T20:52:20Zf5cf2e94c63522e2f1ea72c4def2e5e2e48f6c792df61c0d6818bf8e8b7143b3
APT28Cisco Catalyst SD-WANCitrix NetScalerDNS hijackingF5 BIG-IP APMMITMedge deviceshacktivist activityincident responseoperational guidancepatchingrouter compromiseunauthenticated RCEvulnerability advisory

What happened

The UK NCSC published multiple high‑priority advisories: Russian military‑linked APT28 is actively exploiting vulnerable edge routers to perform DNS hijacking (enabling MITM, credential and token theft); an unauthenticated remote‑code‑execution vulnerability affecting F5 BIG‑IP Access Policy Manager is being pushed as an urgent mitigation; newly disclosed vulnerabilities affect Citrix NetScaler ADC/Gateway and require immediate remediation; and agencies are urging investigation of potential compromises of Cisco Catalyst SD‑WAN. The NCSC also warned of messaging‑app targeting, pro‑Russia hacktv

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
uk_ncsc_all_rss
Record identifier
f5cf2e94c63522e2f1ea72c4def2e5e2e48f6c792df61c0d6818bf8e8b7143b3
Enrichment time
2026-04-07T20:52:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · UK exposes Russian military intelligence hijacking vulnerable routers for cyber attacks · Baitaphish