Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Trusted network links and router abuse: what IAM teams should notice


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: A joint CISA-led advisory tied PRC state-sponsored actors to long-running espionage campaigns that used known edge-device CVEs, trusted interconnections, ACL changes, and credential-harvesting tactics to persist in telecom and government networks, according to SafeBreach coverage of the advisory. The case shows that infrastructure trust, not just perimeter exposure, is now an identity and access problem for security teams.

NHIMG editorial — based on content published by SafeBreach covering CISA Advisory AA25-239A and PRC espionage campaigns: Countering Chinese State-Sponsored Espionage Campaigns

By the numbers:

  • Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, followed by inadequate monitoring and logging at 37% and over-privileged accounts at 37%.

Questions worth separating out

Q: What breaks when device trust is not part of privileged access decisions?

A: Privilege becomes detached from real session risk.

Q: Why does this kind of kernel flaw matter to identity and access teams?

A: Because it compromises the host material that identity systems rely on.

Q: How do organisations know if privileged access controls are working?

A: They are working when standing privilege declines, privileged sessions are shorter, and elevated access is granted only when needed.

Practitioner guidance

  • Inventory privileged network trust paths Map every provider-to-provider, provider-to-customer, and management-plane connection that can alter routing, authentication, or logging.
  • Treat ACL and AAA changes as high-risk identity events Alert on changes to ACLs, TACACS+, RADIUS, SNMP, SSH, and HTTP(S) management settings with the same urgency as privileged IAM changes.
  • Remove standing access from non-essential device services Disable Guest Shell, legacy management ports, and any remote service that is not required for operations.

What's in the full article

SafeBreach's full analysis covers the operational detail this post intentionally leaves for the source:

  • Exact CISA advisory mappings for the actor set, CVEs, and MITRE ATT&CK techniques used in the campaign
  • SafeBreach simulation coverage for router exploitation, credential theft, lateral movement, and covert exfiltration
  • Defensive checks for Guest Shell abuse, non-standard management ports, and suspicious AAA redirection
  • Attack-series validation steps for teams that need to test detections against the advisory's TTPs

👉 Read SafeBreach's analysis of the CISA advisory on PRC espionage campaigns →

Trusted network links and router abuse: what IAM teams should notice?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Trusted infrastructure is becoming an identity problem, not only a network problem. When attackers can pivot through provider links, management services, and router control planes, the practical boundary of IAM extends far beyond human logins. That means security teams should think in terms of governed access paths, not just user accounts, and align network operations with identity governance.

A few things that frame the scale:

  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.

A question worth separating out:

Q: Who is accountable when attackers abuse trusted interconnections for espionage?

A: Accountability is shared across network operations, identity governance, and security leadership because the abused asset is both infrastructure and access control. Frameworks such as NIST CSF and NIST SP 800-53 expect coordinated governance of protection, detection, and authorization, so ownership must extend beyond the network team.

👉 Read our full editorial: PRC router espionage shows how trust relationships become access paths



   
ReplyQuote
Share: