UK exposes Russian military intelligence hijacking vulnerable routers for cyber attacks
2026-04-07T20:52:20Z•f5cf2e94c63522e2f1ea72c4def2e5e2e48f6c792df61c0d6818bf8e8b7143b3
APT28Cisco Catalyst SD-WANCitrix NetScalerDNS hijackingF5 BIG-IP APMMITMedge deviceshacktivist activityincident responseoperational guidancepatchingrouter compromiseunauthenticated RCEvulnerability advisory
What happened
The UK NCSC published multiple high‑priority advisories: Russian military‑linked APT28 is actively exploiting vulnerable edge routers to perform DNS hijacking (enabling MITM, credential and token theft); an unauthenticated remote‑code‑execution vulnerability affecting F5 BIG‑IP Access Policy Manager is being pushed as an urgent mitigation; newly disclosed vulnerabilities affect Citrix NetScaler ADC/Gateway and require immediate remediation; and agencies are urging investigation of potential compromises of Cisco Catalyst SD‑WAN. The NCSC also warned of messaging‑app targeting, pro‑Russia hacktv
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- uk_ncsc_all_rss
- Record identifier
- f5cf2e94c63522e2f1ea72c4def2e5e2e48f6c792df61c0d6818bf8e8b7143b3
- Enrichment time
- 2026-04-07T20:52:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.