The US government warns that Russia state hackers are coming after your router 16%

By Dan Goodin18%

7/13/2026, 2:03:07 PM

BS Summary: This article contains 24 faulty reasoning types, including Framing Effect, Negativity Bias, and Appeal to Authority, with Indoctrination as the most egregious example at 19.2% saturation with 96 hits. Analysis detected 781 faulty-reasoning hits from 499 analyzed words, generating a BS Score of 32.1% and a BS Rank of 16% (18,383 of 21,887 articles). This article is better (less manipulative) than 84.00% of the article peer group.

The federal government is warning users of home and small office routers to secure their devices as Russia state hackers continue to mass-compromise them for use in obscuring nefarious actions against sensitive organizations in the public and private sectors. 
Both the Russian and Chinese governments have been compromising routers for years, sometimes in prolonged tugs-of-war to wrest control of devices the other has already commandeered. 
The US government has occasionally issued covert commands and taken other steps to disinfect routers. 
Google and other companies have also worked to disrupt the massive botnets that control compromised routers in lockstep. 
The actions to date are little more than whack-a-mole exercises as the operators simply replace their botnets with new ones. 
Proxy networks: The go-to tool 
“Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks,” the Cybersecurity and Infrastructure Security Agency said Monday. 
The hacking groups are tracked under various names, including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra. 
The advisory was co-issued by governments from around the world, including Australia, Denmark, New Zealand, and the UK. 
The primary means of compromise the agency warned about was hackers scanning IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default authentication credentials. 
These scans are run by the very sorts of router botnets the actors are trying to enroll the targeted device in. 
By sending malicious traffic from spoofed addresses, the hackers can use the SNMP agent on poorly configured routers to run malware. 
SNMP allows users to collect and organize information about managed networking devices or to modify that information to change device behavior. 
With control of a device, the hackers then use it as an exit node when probing or attacking targets in the communications, defense, energy, financial services, and government sectors. 
By funneling the malicious traffic through a benign-appearing device on a trustworthy IP address, the attackers are able to lower the chances of getting blocked by firewalls and other security defenses. 
Monday’s advisory made no mention of identical operations carried out in recent years by China. 
So-called residential proxies are also a go-to tool used by financially motivated criminal hackers to obscure their true IP address. 
In many cases, these sorts of proxies are made up of millions of streaming devices that are sold with preloaded malware. 
The agency urged router users to lock down their devices. 
Chief among the suggestions is to ensure SNMP versions 1 and 2 are disabled, because they don’t encrypt passwords or follow other common-sense security practices. 
Instead, only SNMP version 3 should be used. 
A better option is to disable SNMP altogether unless it’s needed for a specific use. 
Other safeguards include disabling Cisco Smart Install on all devices, using strong passwords, updating firmware regularly, and avoiding the use of other networking protocols. 
Article reasoning-pattern comparisonThis article: 0.0%Dan Goodin: 0.8%Ars Technica: 2.8%Confirmation Bias0.0%This article: 5.8%Dan Goodin: 0.9%Ars Technica: 1.2%Anchoring Bias5.8%This article: 5.0%Dan Goodin: 3.2%Ars Technica: 2.4%Availability Heuristic5.0%This article: 0.0%Dan Goodin: 1.2%Ars Technica: 1.0%Representativeness Heuristic0.0%This article: 4.2%Dan Goodin: 0.8%Ars Technica: 0.6%Hindsight Bias4.2%This article: 6.2%Dan Goodin: 3.0%Ars Technica: 2.1%Overconfidence Bias6.2%This article: 13.4%Dan Goodin: 2.5%Ars Technica: 3.4%Framing Effect13.4%This article: 5.0%Dan Goodin: 0.3%Ars Technica: 0.5%Loss Aversion5.0%This article: 3.0%Dan Goodin: 0.4%Ars Technica: 0.5%Status Quo Bias3.0%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.1%Sunk Cost Effect0.0%This article: 4.8%Dan Goodin: 1.0%Ars Technica: 4.2%Optimism Bias4.8%This article: 4.0%Dan Goodin: 2.9%Ars Technica: 1.7%Pessimism Bias4.0%This article: 10.8%Dan Goodin: 6.6%Ars Technica: 6.2%Negativity Bias10.8%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 1.2%Self-Serving Bias0.0%This article: 0.0%Dan Goodin: 0.8%Ars Technica: 0.6%Fundamental Attribution Error0.0%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.1%Actor-Observer Bias0.0%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.6%In-Group Bias0.0%This article: 5.2%Dan Goodin: 0.9%Ars Technica: 0.2%Out-Group Homogeneity Bias5.2%This article: 3.6%Dan Goodin: 0.8%Ars Technica: 2.0%Halo Effect3.6%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.1%Horn Effect0.0%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.0%Dunning-Kruger Effect0.0%This article: 0.0%Dan Goodin: 1.0%Ars Technica: 1.0%Recency Bias0.0%This article: 0.0%Dan Goodin: 0.2%Ars Technica: 0.3%Primacy Effect0.0%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.1%Blind-Spot Bias0.0%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.5%Ad Hominem0.0%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.2%Straw Man0.0%This article: 10.4%Dan Goodin: 3.2%Ars Technica: 4.1%Appeal to Authority10.4%This article: 7.4%Dan Goodin: 1.3%Ars Technica: 1.1%False Dilemma7.4%This article: 0.0%Dan Goodin: 0.2%Ars Technica: 0.7%Slippery Slope0.0%This article: 4.2%Dan Goodin: 0.2%Ars Technica: 0.1%Circular Reasoning4.2%This article: 8.2%Dan Goodin: 7.0%Ars Technica: 3.8%Hasty Generalization8.2%This article: 0.0%Dan Goodin: 0.4%Ars Technica: 0.2%Red Herring0.0%This article: 0.0%Dan Goodin: 0.8%Ars Technica: 0.6%Bandwagon0.0%This article: 0.0%Dan Goodin: 1.0%Ars Technica: 2.7%Appeal to Emotion0.0%This article: 0.0%Dan Goodin: 0.1%Ars Technica: 0.6%Begging the Question0.0%This article: 0.0%Dan Goodin: 2.2%Ars Technica: 2.3%Post Hoc (False Cause)0.0%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.2%Tu Quoque0.0%This article: 0.0%Dan Goodin: 0.1%Ars Technica: 0.5%Burden of Proof0.0%This article: 5.0%Dan Goodin: 0.8%Ars Technica: 0.2%Appeal to Nature5.0%This article: 4.8%Dan Goodin: 0.9%Ars Technica: 0.2%Composition/Division4.8%This article: 5.2%Dan Goodin: 0.5%Ars Technica: 1.5%Anecdotal5.2%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.1%No True Scotsman0.0%This article: 4.2%Dan Goodin: 6.6%Ars Technica: 1.7%Ambiguity (Equivocation)4.2%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.0%Gambler’s Fallacy0.0%This article: 3.0%Dan Goodin: 0.3%Ars Technica: 0.1%Middle Ground3.0%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.1%Personal Incredulity0.0%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.1%Special Pleading0.0%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.1%Genetic Fallacy0.0%This article: 6.8%Dan Goodin: 1.8%Ars Technica: 1.5%Unattributed Quote6.8%This article: 6.8%Dan Goodin: 2.9%Ars Technica: 1.0%Quote-first Misdirection6.8%This article: 0.0%Dan Goodin: 4.0%Ars Technica: 4.5%Biased Writer Voice0.0%This article: 19.2%Dan Goodin: 2.2%Ars Technica: 1.0%Indoctrination19.2%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.7%Politically Left Leaning Bias0.0%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 0.2%Politically Right Leaning Bias0.0%This article: 0.0%Dan Goodin: 0.0%Ars Technica: 1.3%Attempt to Sell a Product or S…0.0%

499 words analyzed.

Speakers

1speaker24%attributed speech378writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 13 words • 0.0% coverageWriter's voice • 39 words • 100.0% coverageWriter's voice • 26 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageCybersecurity and Infrastructure Security Agency • 34 words • 100.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageCybersecurity and Infrastructure Security Agency • 29 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 29 words • 0.0% coverageWriter's voice • 31 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageCybersecurity and Infrastructure Security Agency • 10 words • 100.0% coverageCybersecurity and Infrastructure Security Agency • 25 words • 0.0% coverageCybersecurity and Infrastructure Security Agency • 8 words • 100.0% coverageCybersecurity and Infrastructure Security Agency • 15 words • 100.0% coverageWriter's voice • 24 words • 100.0% coverage
100%flagged-word coverage
121 attributed words100% of attributed speech68% writer coverage
0%15.0%30.0%Unattributed Quote+28.1 ptsWriter: 0.0%Cybersecurity and Infrastructure Security Agency: 28.1%28.1%Quote-first Misdirection+28.1 ptsWriter: 0.0%Cybersecurity and Infrastructure Security Agency: 28.1%28.1%Indoctrination+10.6 ptsWriter: 16.7%Cybersecurity and Infrastructure Security Agency: 27.3%27.3%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.