A Ninth Warning About the Same Adversary
On July 13, 2026, the NSA, CISA, the FBI and the Department of Defense Cyber Crime Center, joined by cybersecurity agencies from eight allied nations, published a joint advisory — AA26-194A, "Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting" — describing an active campaign by Russia's FSB Center 16, tracked across the industry as Berserk Bear, Energetic Bear, Dragonfly and, most recently, Static Tundra, against routers and network devices in the communications, energy, defense, financial services, healthcare and state/local government sectors (CISA; SecurityInfoWatch).
The technique is unglamorous. Center 16 operators scan public IP ranges for routers still running SNMPv1/v2 with default or common "community string" credentials, send spoofed SNMP Set-Requests instructing the device to dump its configuration file, then pull that file off over TFTP to an actor-controlled server. Where SNMP isn't exposed, the group falls back on Cisco's years-old Smart Install protocol, which many organizations never got around to disabling (SecurityInfoWatch). None of this requires a zero-day.
Not a New Campaign, a Persistent One
What makes AA26-194A notable isn't the technique — it's the repetition. This is the same actor cluster the Justice Department indicted in March 2022, when it unsealed charges against three FSB Center 16 officers, Pavel Akulov, Mikhail Gavrilov and Marat Tyukov, for a campaign that between 2012 and 2017 compromised thousands of computers at hundreds of organizations in roughly 135 countries, including nuclear power plants and utility operators (DOJ). CISA issued its own advisory on the group's energy-sector tradecraft that same month — AA22-083A, covering intrusions dating back to 2011 (CISA AA22-083A). Four years, one federal indictment and a prior joint advisory later, the group is still getting in through the same category of failure: devices left with default credentials on legacy management protocols.
That persistence is the real policy story. If a decade of public attribution, an unsealed indictment and a previous CISA advisory haven't closed this attack surface, "raise awareness and hope operators patch" has reached the limit of what it can do on its own for equipment already sitting in production networks.
The Case for a Mandate
There's a genuine argument for going further than another advisory. Default and weak credentials aren't a sophisticated failure — they're a design choice manufacturers keep making because nothing compels them to stop, and the cost of an FSB foothold in a utility's network falls on the public, not the vendor. The EU's Cyber Resilience Act, whose core security-by-design obligations for networked hardware begin applying from December 2027, reflects a judgment that voluntary hygiene campaigns have had years to work and largely haven't. A Congress persuaded that critical-infrastructure routers are a national-security good, not an ordinary consumer product, could reasonably legislate a no-default-password requirement with real enforcement, rather than leaving it to advisories that read the same in 2026 as they did in 2022.
Why Procurement Leverage Fits Better Than a Statute
The weakness in that case is that it targets the wrong end of the problem. The routers Center 16 is exploiting today are already deployed. A statute governing future manufacturing wouldn't touch a single one of them, and any rulemaking would take years to reach the hardware already sitting in a rural utility's server closet. What actually reaches the installed base is exactly what AA26-194A does: a specific, executable list — disable Smart Install, migrate to SNMPv3 with authPriv encryption, kill default community strings, block ports 69, 161-162 and 4786 at the perimeter — that an operator can act on this week.
On the manufacturing side, the U.S. already has a lever that doesn't require new legislation: procurement. The FCC's U.S. Cyber Trust Mark, now administered by the ioXt Alliance after its original administrator withdrew mid-2026, is expanding its voluntary labeling program to cover home and small-office routers, and vendors supplying consumer IoT products to the federal government will be required to carry the mark by January 2027 (FCC). That's the more proportionate instrument: it uses the government's own buying power to push default-credential-free design into the market on a defined timeline, without imposing a new compliance regime on every router sold domestically or waiting on a legislative process that would likely lag the threat the way the 2022 indictment lagged the underlying intrusions — by up to a decade.
The Proportionate Read
None of this excuses vendors who still ship SNMP defaults live out of the box, and Congress has every reason to press the FCC on why its own IoT labeling program spent months mired in an administrator dispute while the same Russian unit kept popping routers. But the right test for the policy response to AA26-194A is whether it fixes the routers that exist today, not just the ones built tomorrow. Operational hardening guidance paired with procurement-driven labeling gets there faster than a new statutory mandate would — and speed, after fifteen years of the same trick working, is what this campaign actually calls for.