Russian campaign exploits misconfiguration, not vulnerabilities, in edge devices

Amazon Threat Intelligence has published an account of a Russian state-sponsored campaign with activity from 2021 to the present. What Amazon highlights as new is a shift in method: the group increasingly exploits misconfigurations in customers' network edge devices rather than hunting for vulnerabilities. The victims are critical infrastructure organisations in Europe, North America and the Middle East.

What this means for your organisation

Vulnerability management does not catch this. A firewall or VPN concentrator can be fully patched and still stand open because a rule was added temporarily, a management interface was exposed, or a default account was never removed. For Norwegian organisations in energy, transport, health and water, this means NIS2 compliance cannot be measured in patches installed alone. Configuration must be documented and verified as systematically as patch level.

Berigo recommends

  • Review every internet-facing device and confirm that management interfaces are not reachable from outside.
  • Establish a baseline configuration for firewalls, VPNs and routers, and report deviations against it regularly.
  • Remove unused accounts, default accounts and temporary rules, and give every rule you open a fixed expiry.
  • Enable and centrally retain logs from edge devices so activity can be traced after an intrusion.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch