Ubiquiti EdgeRouters hacks may be everywhere

The free patch the FBI applied last week may not be enough

Last week, the FBI sought and received court approval to quietly roll out an update for Ubiquiti SOHO routers, which you may or may not be aware of. They added firewall rules to prevent these routers from being hijacked by the Russian hacking group APT28, and they were disturbingly effective at doing so. Once they gain access to the router, they will ignore your traffic to help hide their activity and instead use it to launch attacks. Since these SOHO routers are unlikely to be blacklisted, and due to the sheer volume they operate in, sites they attack from these routers will not immediately block traffic.

The new firewall settings the FBI added to these routers should prevent the spread of new infections, but do not address the root cause. It is highly recommended that anyone running a Ubiquiti router take a few steps. It’s a very good idea to reset your router to factory settings, then upgrade to the latest firmware, and finally do what you should do; get rid of any default passwords and usernames!

Once you’ve done this, you may want to consider tightening your firewall rules, as attacks will evolve and persist.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *