19 Government Agencies Just Co-Signed the Same Warning: The Device in Your Closet Is a Target.
On July 13, nineteen agencies across thirteen countries put their names on a single cybersecurity advisory. The subject wasn't a sophisticated new exploit. It was routers and switches — the network boxes sitting in closets and utility cupboards that nobody has logged into since the day they were installed. The attackers aren't breaking in with a zero-day. They're walking in through default settings that were never changed. Here's what the warning says, and the handful of fixes that close the door.
It's rare for cybersecurity agencies to agree loudly and in unison. Nineteen of them doing so, across thirteen countries, on a single advisory, is close to unprecedented — and it's worth asking why a threat that requires no malware and no zero-day exploit earned that level of coordinated alarm.
The answer is uncomfortable: because the technique is so simple, so effective, and so widely applicable that the agencies concluded almost everyone is exposed. The advisory, published July 13, 2026, describes state-sponsored actors systematically scanning the internet for network devices — routers, switches, and the management services that run on them — that still accept default or common configuration credentials. When they find one, they copy its configuration file, which contains the credentials and network details they need to go deeper. No break-in. No exploit. Just a device answering to a password that was never changed.
government agencies across 13 countries co-signed a single advisory about one threat
Led by the US National Security Agency, CISA, and the FBI, and joined by partner agencies across Europe, the UK, Canada, Australia, and New Zealand, the advisory carries unusual weight precisely because so many independent bodies agreed it was urgent. The threat they're describing isn't exotic. It's the network hardware almost every organization runs — and the configuration mistakes almost every organization has made and forgotten.
Here's why this matters for a small business, even one that would never consider itself "critical infrastructure." The advisory notes the actors are compromising devices opportunistically — that is, they scan broadly and take what answers, rather than picking targets in advance. A scan doesn't know or care whether the device it finds belongs to a power utility or a fifteen-person accounting firm. If your router is internet-reachable and running a default configuration, you're in the same scan results as everyone else. The targeting is automated, and automation doesn't discriminate by company size.
How the attack works — no malware required
What makes this advisory unsettling is how little the attackers have to do. The core technique is almost mundane:
Why the network device is the perfect blind spot
Every business protects its computers. Antivirus, updates, MFA on the email — that's where attention goes, because those are the things people touch every day. The router is different. It gets installed once, it works, and it becomes furniture. Nobody logs into it. Nobody updates its firmware. Nobody remembers the password, because the password is still whatever it was in the box. It sits there for years, quietly doing its job, connected directly to the internet — which is exactly what makes it the ideal target.
The fixes — cheap, specific, and mostly one-time
The reassuring half of this story is that the defenses are unglamorous configuration changes, not expensive tools. Because the exposure is configuration-based, fixing the configuration meaningfully reduces the risk. Here's the practical version for a small business.
Change the default access strings and passwords on every network device
Free · Do firstThis is the fix that closes the specific door in the advisory. Every router, switch, and firewall should have its factory-default management credentials and configuration access strings changed to something unique and strong. If you don't know how, your device's support documentation or your IT provider can do it in minutes. This single step defeats the primary technique described.
Make sure device management isn't reachable from the internet
Free · CriticalThe attack only works if the device's management service can be reached from outside your network. Management interfaces should be accessible only from inside your network, never from the public internet. Ask your IT provider to confirm your router's admin interface and management protocols are not exposed externally — this is a common and dangerous default.
Turn off legacy management protocols you don't need
FreeOlder versions of the management protocol abused in this campaign send information without encryption and should be disabled in favor of a modern, authenticated, encrypted version. If a legacy feature or auto-configuration service isn't actively needed, turning it off removes an entire category of risk. Your IT provider can identify and disable what you're not using.
Update firmware — and replace gear that's too old to update
Low costNetwork devices need updates just like computers do. Apply the latest firmware to your routers and switches, and budget to replace any device so old the manufacturer no longer supports it. End-of-life hardware that can't be patched is a standing liability — one such old router flaw was added to the confirmed-exploited catalog alongside this very advisory.
The connection to everything else
This advisory is the "123456 password" problem from our earlier writing, moved from the login screen to the network closet. It's the same lesson as the dead-credential breach that took down hundreds of companies: the most damaging attacks routinely start not with brilliance but with something that was left in its default state and forgotten. The attackers here are among the most sophisticated in the world — and their way in is a password nobody changed.
It's also a live example of why our Threat Intelligence feed leads with what's confirmed to be actively exploited. Alongside this advisory, an old network-device vulnerability was added to the government's confirmed-exploited catalog — exactly the kind of signal that should jump to the top of any business's list, ahead of a hundred theoretical issues. Knowing which threat is real and current, and what to do about it first, is the whole game. The device in your closet just moved to the top of the list.
See which threats are confirmed active right now — free, live, and in plain language for small business.
View the Threat Intelligence feed → Find Out More About Veriti Spottr →📚 Credential Security Series — Read the full series

Comments
Post a Comment