Your router may be vulnerable to Russian hackers, FBI warns: 5 steps to take now


tp-link-deco-be77-image-2-vents.png

Cesar Cadenas/ZDNET

Follow ZDNET: Add us as a preferred source on Google.


ZDNET’s key takeaways

  • The FBI and NSA are warning of new threats targeting routers.
  • Attacks from Russian hackers can compromise your router.
  • Update the firmware and tighten your router password.

When was the last time you updated or restarted your router? As long as your internet is working, you may set up your router and then forget about it. But based on new alerts from US federal agencies, that’s not such a good idea.

In new advisories published this week, both the FBI and NSA warned of Russian hackers targeting vulnerable routers around the world to steal sensitive information. Though the attackers are mostly interested in military and government secrets, home and small office users are also at risk. That’s because the attackers will hijack SOHO (small office, home office) routers from which they can stage their attacks.

Also: Your home Wi-Fi isn’t nearly as private as it should be – 6 free ways to lock it down

In one recent incident, the US Department of Justice and the FBI disrupted a network of compromised SOHO routers that the Russian GRU (General Staff Main Intelligence Directorate) had exploited to carry out malicious DNS hijacking operations. As Russia’s military-based spy agency, the GRU is infamous for committing acts of espionage and more violent types of attacks against foreign adversaries.

In its warnings, the FBI and NSA announced that members of the GRU cybercrime group APT28 (aka Fancy Bear and Forest Blizzard) have been stealing login credentials from compromised routers, including older, legacy TP-Link routers. In its own advisory for the CVE-2023-50224 vulnerability, TP-Link said that many of its products are affected, but that all of them have reached end-of-life status, which means they are no longer supported by the company.

Also: A $30 router with a built-in VPN? I had to try it – and haven’t had any regrets

The US government has already been weighing a ban of TP-Link routers, charging that the devices are vulnerable to security threats and are tied to China as the manufacturer’s country of origin. The company has fought back against these charges, arguing that China has no control over its products and that all the core data security functions are handled within the US.

Beyond TP-Link’s status, the FBI and NSA clearly see Russia’s GRU as a threat.

“The GRU has harvested passwords, authentication tokens, and sensitive information, including emails and web browsing information normally protected by secure socket layer (SSL) and transport layer security (TLS) encryption,” the FBI revealed. “The GRU has indiscriminately compromised a wide pool of US and global victims and then filtered down impacted users, especially targeting information related to military, government, and critical infrastructure.”

How to protect your router (and yourself)

Whether or not your router is vulnerable to these types of attacks, there are certain steps you should take to protect your device, your data, and yourself.

1. Change your router password

Every router comes with a default username and password to access its firmware. (This is different than the password you create for your Wi-Fi network.) But sticking with the default credentials is risky, so you should change them ASAP. 

Also: Traditional Wi-Fi router vs. mesh: How to decide between the 2 popular networking options

Sign in to your router’s firmware, look for the password setting, and set a new one. Follow the same advice you normally would when creating a strong password–something complex but memorable. You can also use a passphrase, which is just as secure as a good password, if not more so, and can be easier to remember.

2. Update the firmware

Router manufacturers periodically roll out new firmware in response to security holes and other bugs. In your router’s firmware, check the firmware update setting to see if any new versions are available, and then download and install them.

3. Upgrade an older router

An older, legacy router that has reached end-of-life status may no longer be supported by the manufacturer. That means you won’t receive firmware updates or security patches. To check your current router’s status, run a search for it or contact the manufacturer. If your router falls into this end-of-life category, replace it with a newer model that is supported.

4. Disable or tighten remote management

Most routers offer ways for you to manage or access them remotely from the public internet. That’s certainly convenient, but it can open up your device to hackers, especially if your password is weak or the router is otherwise vulnerable. Review the firmware settings to see if remote access is enabled. If so, consider disabling it or tightening the overall security to prevent unauthorized access.

Also: It’s time to admit your router’s built-in firewall isn’t enough – here’s what is

5. Periodically restart your router

Here’s one more piece of advice from an NSA Best Practices document. To combat any nonpersistent malware that may reside on your router, consider restarting it periodically, as often as once a week. This will remove any lingering, nonpersistent infections. If you already restart your router from time to time to deal with internet problems, then this is one more reason to do so.





Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Serials have become the backbone of the streaming era, especially on Netflix. Serialized television is when a show’s plot unfolds in sequential order over the course of a season. It’s long-form storytelling that typically works best with dramas—Stranger Things, The Crown, etc. Watching the episodes in release order matters. Often, these shows are binged because the complex character arcs and cliffhangers encourage streaming multiple episodes at once.

Serial shows can feel like homework, especially when you fall behind on an episode and need to catch up. That always happens to me, and it leads to anxiety I didn’t want. Thankfully, Netflix offers shows where viewers can jump at any time and not feel lost. These episodic series are perfect for jumping around and picking the episodes you want to watch. One of the most famous comedies ever fits the criteria of an episodic sitcom. Anthology shows, including a Netflix sci-fi classic, are also ideal for watching episodes out of order.

Black Mirror

Welcome to your worst nightmare

Black Mirror wants to scare you. Charlie Brooker’s sci-fi anthology series has been warning humanity about the dangers of technology since 2011. It seems like ages ago that Rory Kinnear had sexual intercourse with a pig in the first episode. Apologies for the spoiler, but the media’s role in the spread of misinformation has never been more relevant.

Black Mirror features self-contained episodes with a beginning, middle, and an end. There has only been one direct sequel: USS Callister: Into Infinity, a season 7 episode that continues the events of season 4’s USS Callister. Otherwise, feel free to jump around and check out the best episodes of each season. Since most episodes feature bleak endings, I’ll leave you with one that ends on an upbeat note: San Junipero.

Seinfeld

Greatest comedy ever?

Comedies are the perfect vehicle for episodic storytelling. While having an overarching plot throughout a season helps attract viewers, many comedy fans are just looking for a few laughs. Write a self-contained story with numerous jokes over 20 to 30 minutes, and you’re ready to go. Seinfeld, aka the show about nothing, is the ideal escape from serialized dramas.

Seinfeld stars Jerry Seinfeld as a fictionalized version of himself as he navigates the comedic scene in New York City. The show revolves around Jerry’s interactions with his friends George (Jason Alexander), Elaine (Julia Louis-Dreyfus), and Kramer (Michael Richards). The gang faces a problem, hilarity ensues, and the episode ends. That’s really all you need to know. Enjoy the laughs.

Guillermo del Toro’s Cabinet of Curiosities

The genre maestro curates new horror stories

There’s a reason why Guillermo del Toro is considered the “King of the Monsters.” The genre expert is as elite as it comes when dealing with mythology and creating new worlds. The Oscar winner relied on his horror expertise in the anthology series Guillermo del Toro’s Cabinet of Curiosities.

I hate referring to episodes of television as “mini-movies.” However, that’s how I would describe the eight episodes of Cabinet of Curiosities. Each director puts their own signature style on a story and brings audiences into their terrifying creation. Del Toro wrote two of the episodes, including one about a demon being summoned. Some are scarier than others, but horror fans will feel right at home with this series. ​​​​​​​

Beat Bobby Flay

Bobby brings the heat

As I’ve gotten older, the Food Network has become one of my favorite channels. I mean, who doesn’t love food? I love eating my (average) home-cooked meal while watching contestants duke it out in the kitchen on my favorite show, Beat Bobby Flay. The competition breaks down into two rounds. In the first round, two chefs have 20 minutes to construct a meal using a secret ingredient. The winner advances to the main event, where they face off against Bobby Flay.

The challenger gets to pick the dish for the final round, so Bobby has a disadvantage. However, Bobby is an award-winning chef with a few tricks up his sleeves. He can handle making a version of your grandmother’s lasagna. With episodes available on Netflix, be prepared to learn why Bobby always throws chiles into his dishes.​​​​​​​

S.W.A.T.

Broadcast TV still knows how to make entertaining programs

The procedural is a genre best produced on broadcast television. Name a cop, doctor, or law drama—chances are it’s a procedural on broadcast TV. While the way we watch television has changed, people still love these types of shows on CBS, NBC, Fox, and ABC. Law & Order, NCIS, and Criminal Minds are procedurals that gained a bigger following thanks to streaming.

S.W.A.T. is cut from the same cloth as Chicago P.D. and CSI. Sergeant Daniel “Hondo” Harrelson (Shemar Moore) is tasked with leading a new S.W.A.T. unit in the LAPD. This action-packed show utilizes a “case of the week” formula in which the team must solve a dangerous situation, such as active shooters and hostage situations. You’re in and out in 44 minutes. What’s better than that?​​​​​​​


Netflix has more content coming your way

After you’re done watching these shows, stay on Netflix for more top-notch content. Netflix has an entire section dedicated to thrillers, and this week, The Guilty and El Camino are two of the section’s best. Keep an eye out for new movies, like Alan Ritchson’s War Machine, which is currently in the streamer’s top 10.

Subscription with ads

Yes, $8/month

Simultaneous streams

Two or four




Source link