19 Government Agencies Just Co-Signed the Same Warning: The Device in Your Closet Is a Target.

Government Advisory Network Security
July 2026  ·  7 min read

On July 13, nineteen agencies across thirteen countries put their names on a single cybersecurity advisory. The subject wasn't a sophisticated new exploit. It was routers and switches — the network boxes sitting in closets and utility cupboards that nobody has logged into since the day they were installed. The attackers aren't breaking in with a zero-day. They're walking in through default settings that were never changed. Here's what the warning says, and the handful of fixes that close the door.


It's rare for cybersecurity agencies to agree loudly and in unison. Nineteen of them doing so, across thirteen countries, on a single advisory, is close to unprecedented — and it's worth asking why a threat that requires no malware and no zero-day exploit earned that level of coordinated alarm.

The answer is uncomfortable: because the technique is so simple, so effective, and so widely applicable that the agencies concluded almost everyone is exposed. The advisory, published July 13, 2026, describes state-sponsored actors systematically scanning the internet for network devices — routers, switches, and the management services that run on them — that still accept default or common configuration credentials. When they find one, they copy its configuration file, which contains the credentials and network details they need to go deeper. No break-in. No exploit. Just a device answering to a password that was never changed.

19

government agencies across 13 countries co-signed a single advisory about one threat

Led by the US National Security Agency, CISA, and the FBI, and joined by partner agencies across Europe, the UK, Canada, Australia, and New Zealand, the advisory carries unusual weight precisely because so many independent bodies agreed it was urgent. The threat they're describing isn't exotic. It's the network hardware almost every organization runs — and the configuration mistakes almost every organization has made and forgotten.

Here's why this matters for a small business, even one that would never consider itself "critical infrastructure." The advisory notes the actors are compromising devices opportunistically — that is, they scan broadly and take what answers, rather than picking targets in advance. A scan doesn't know or care whether the device it finds belongs to a power utility or a fifteen-person accounting firm. If your router is internet-reachable and running a default configuration, you're in the same scan results as everyone else. The targeting is automated, and automation doesn't discriminate by company size.

How the attack works — no malware required

What makes this advisory unsettling is how little the attackers have to do. The core technique is almost mundane:

The technique, in four steps
1
Scan the internet. Automated scans sweep broad ranges of internet addresses looking for network devices whose management protocol is reachable from outside and still accepts a default or commonly used access string.
2
Ask the device to talk. Because the access string was never changed from the factory default, the device answers to a stranger's request as readily as it would to its own administrator. No password cracking, no exploit — the door simply isn't locked.
3
Copy the configuration. The attackers instruct the device to send them a copy of its configuration file, which they retrieve over a simple file-transfer protocol. That file is a map of the network — and it contains credentials.
4
Pivot deeper. Armed with the credentials and topology from the config, the actors move further into the network — quietly, using legitimate access, in a way that looks like normal administration rather than an intrusion.
The single most important sentence in the entire advisory, translated into plain English: your router does not need a zero-day to be compromised. A default configuration string is enough. The overwhelming majority of the exposure here is configuration-based — settings that could have been changed at any point in the last several years and simply weren't, because the device works fine and nobody had a reason to open it.
No malware is used in the primary technique — the attack relies entirely on default settings and reachable management services, so antivirus never sees a thing Joint Advisory AA26-194A, July 2026
6 sectors named as high-risk — communications, defense, energy, financial services, government, and healthcare — but the scans are indiscriminate Joint Advisory AA26-194A
15+ yrs the campaign has reportedly been running — a slow, patient effort to map networks through their least-watched devices Advisory / DOJ 2022 indictment

Why the network device is the perfect blind spot

Every business protects its computers. Antivirus, updates, MFA on the email — that's where attention goes, because those are the things people touch every day. The router is different. It gets installed once, it works, and it becomes furniture. Nobody logs into it. Nobody updates its firmware. Nobody remembers the password, because the password is still whatever it was in the box. It sits there for years, quietly doing its job, connected directly to the internet — which is exactly what makes it the ideal target.

Think about your own setup honestly. When did anyone last log into your router or firewall? Do you know whether its management interface is reachable from the internet? Has its firmware ever been updated since it was installed? Is it still running the password it shipped with? For most small businesses, the honest answers are: never, no idea, no, and probably. That's not negligence — it's just that the device was never on anyone's list. This advisory is the reason to put it on the list.

The fixes — cheap, specific, and mostly one-time

The reassuring half of this story is that the defenses are unglamorous configuration changes, not expensive tools. Because the exposure is configuration-based, fixing the configuration meaningfully reduces the risk. Here's the practical version for a small business.

1

Change the default access strings and passwords on every network device

Free · Do first

This is the fix that closes the specific door in the advisory. Every router, switch, and firewall should have its factory-default management credentials and configuration access strings changed to something unique and strong. If you don't know how, your device's support documentation or your IT provider can do it in minutes. This single step defeats the primary technique described.

2

Make sure device management isn't reachable from the internet

Free · Critical

The attack only works if the device's management service can be reached from outside your network. Management interfaces should be accessible only from inside your network, never from the public internet. Ask your IT provider to confirm your router's admin interface and management protocols are not exposed externally — this is a common and dangerous default.

3

Turn off legacy management protocols you don't need

Free

Older versions of the management protocol abused in this campaign send information without encryption and should be disabled in favor of a modern, authenticated, encrypted version. If a legacy feature or auto-configuration service isn't actively needed, turning it off removes an entire category of risk. Your IT provider can identify and disable what you're not using.

4

Update firmware — and replace gear that's too old to update

Low cost

Network devices need updates just like computers do. Apply the latest firmware to your routers and switches, and budget to replace any device so old the manufacturer no longer supports it. End-of-life hardware that can't be patched is a standing liability — one such old router flaw was added to the confirmed-exploited catalog alongside this very advisory.

Notice what's not on this list: no new product to buy, no security team to hire, no complex deployment. Four configuration changes, most of them free and one-time, close the door on a threat that nineteen governments considered urgent enough to warn the world about together. This is the recurring pattern of this entire series — the attack sounds like something only a nation-state could pull off, and the defense is changing a password and turning off a setting you weren't using.

The connection to everything else

This advisory is the "123456 password" problem from our earlier writing, moved from the login screen to the network closet. It's the same lesson as the dead-credential breach that took down hundreds of companies: the most damaging attacks routinely start not with brilliance but with something that was left in its default state and forgotten. The attackers here are among the most sophisticated in the world — and their way in is a password nobody changed.

It's also a live example of why our Threat Intelligence feed leads with what's confirmed to be actively exploited. Alongside this advisory, an old network-device vulnerability was added to the government's confirmed-exploited catalog — exactly the kind of signal that should jump to the top of any business's list, ahead of a hundred theoretical issues. Knowing which threat is real and current, and what to do about it first, is the whole game. The device in your closet just moved to the top of the list.

See which threats are confirmed active right now — free, live, and in plain language for small business.

View the Threat Intelligence feed → Find Out More About Veriti Spottr →
VS
Veriti Spottr Team AI-powered cyber risk clarity for SMBs  ·  veritispottr.com

Comments

Popular posts from this blog

The Hidden Cost of Cybersecurity Inaction for Small Businesses

Small Business Ransomware Protection Guide (2026 Edition)

Your Biggest Cyber Risk Isn't Outside Your Firewall. It's on Your Payroll.