Fun fact. Or maybe it’s not so fun. The Russians have been exploiting security vulnerabilities for years in home ad small office routers. In the process the Russians can use these routers to execute attacks at will. Thus the The FBI and NSA took the really unusual step of getting a court order in order to find and remotely reset these routers to kick the Russians out of these routers. Though there’s a catch to that which I will get to in a moment. From CNET:
Federal agencies, including the FBI and NSA, disclosed on April 7 that a unit of Russia’s military intelligence directorate, the GRU group known as APT28 or Fancy Bear, has been systematically compromising home and small office routers since at least 2024, using the access to intercept credentials, authentication tokens and sensitive communications. The agency took the unusual step of remotely resetting thousands of affected US devices under a court order, but officials are warning that without action from individual router owners, the problem is far from solved.
Here’s the catch. The routers in question aren’t getting security updates as well. So it is entirely likely that the Russians can simply come back and set up shop again if you leave the router in operation. Thus if your router gets reset remotely, it needs to be replaced. Immediately. As in now. Today.
If you’re wondering which routers are targeted, CNET can help you with that:
The UK’s National Cyber Security Centre includes a number of TP-Link routers specifically targeted by the hackers.
But I would not consider that list to be complete. Which is why you should replace your router if it factory reset remotely. Consider this a today problem.
NSA’s Cyber Hygiene Best Practices Name the Right Threats But Answer With Wrong Architecture
Posted in Commentary with tags NSA on September 4, 2026 by itnerdThe National Security Agency released its best practices for cyber hygiene yesterday but created some confusion for users in its identification of threats and suggestions of wrong architecture according to AI and cybersecurity expert, Chris Nyhuis, who is CEO of Vigilant:
“My thoughts are that the NSA didn’t get it necessarily wrong but they also didn’t get it right. The guidance names the right threat and then answers it with the wrong architecture. It correctly identifies AI-accelerated living off the land activity as the core problem, then recommends endpoint detection, log aggregation, and behavioral baselines, which are the three things that fail hardest against an attacker using legitimate signed binaries. It tells defenders to baseline traffic and detect anomalies but never requires them to actually capture that traffic. The segmentation guidance leans on next-generation firewalls, and firewalls are themselves an attack surface: they get exploited, misconfigured, and turned into the pivot point. You need collection in front of that control plane, a passive tap and full-stack detection that sees the traffic regardless of whether the enforcement device is trustworthy or still under your control. Behavioral learning has the same problem. AI-driven attackers can pace themselves to the baseline, introduce entropy, and shape their own activity into what the model has already learned to call normal. A system trained to recognize normal is a system an adversary can teach. The answer is not more defensive AI reviewing yesterday’s logs; it is network evidence you actually hold and human forensic validation on top of it. “
Hopefully the NSA hears this feedback and “gets it”. Because advice like this only works if everybody listens.
Leave a comment »