SEV2 — MajorCLOSEDCyberONGOING✓ Corroborated · 5 sources18d ago

Russian State-Sponsored Router Targeting Advisory — Des Moines Operations Footprint at Risk

A Sev-10 sentinel alert flags active Russian state-sponsored targeting of router infrastructure in the Des Moines area, mirroring the campaign pattern already declared for Oklahoma. Des Moines carries a substantial knowledge-worker and back-office footprint (~78,000+ seats combined), making network-layer compromise a credible risk to VPN access, remote-agent connectivity, and site communications. Operations leaders should verify router hygiene posture at Des Moines hubs and confirm that IT security teams are applying CISA-recommended mitigations; the Zimbra account-hijack flaw (7 articles, Sev 4) adds a secondary email-vector concern worth monitoring but does not independently drive this declaration. Affected regions: Colorado Springs, Des Moines, Dfw, Denver

Impact Summary

A Sev-10 sentinel alert flags active Russian state-sponsored targeting of router infrastructure in the Des Moines area, mirroring the campaign pattern already declared for Oklahoma. Des Moines carries a substantial knowledge-worker and back-office footprint (~78,000+ seats combined), making network-layer compromise a credible risk to VPN access, remote-agent connectivity, and site communications. Operations leaders should verify router hygiene posture at Des Moines hubs and confirm that IT security teams are applying CISA-recommended mitigations; the Zimbra account-hijack flaw (7 articles, Sev 4) adds a secondary email-vector concern worth monitoring but does not independently drive this declaration.

Domain
Cyber
Region
Des Moines, US, US
Opened By
watchkeeper
Jul 14, 2026, 03:00 PM UTC
Event Cluster
6 events
OVIX Score
10.0
Closed
System(foreman-stale-cleanup)
Jul 20, 2026, 06:27 PM UTC

Timeline12

Incident openedby watchkeeperJul 14, 2026, 03:00 PM UTC
Declared from 1 signals. OVIX 10. News 3. BPO 1. High-confidence (auto). Flagged persistent (ongoing situation).
Note addedby watchkeeperJul 14, 2026, 03:00 PM UTC
External corroboration: corroborated (5 sources via Exa). bleepingcomputer.com, arstechnica.com, ncsc.govt.nz, cyberscoop.com, infosecurity-magazine.com
Note addedby watchkeeperJul 15, 2026, 03:30 PM UTC
Merged new cluster (1 signals, OVIX 10, regions Colorado Springs) — same underlying entity. Entity identity vendor:router+russian — collapsed across regions (agents-036 Gate 3, <14d window).
Note addedby watchkeeperJul 15, 2026, 03:30 PM UTC
SEV1 candidate: multi-region OVIX 10 with fresh events. Held at SEV2 — requires human validation to promote to SEV1 (spec §2).
Note addedby watchkeeperJul 15, 2026, 04:00 PM UTC
Merged new cluster (1 signals, OVIX 10, regions Colorado Springs) — same underlying entity. Entity identity vendor:router+russian — collapsed across regions (agents-036 Gate 3, <14d window).
Note addedby watchkeeperJul 15, 2026, 09:30 PM UTC
Merged new cluster (1 signals, OVIX 10, regions Dfw) — same underlying entity. Entity identity vendor:router+russian — collapsed across regions (agents-036 Gate 3, <14d window).
Note addedby watchkeeperJul 15, 2026, 10:00 PM UTC
Merged new cluster (1 signals, OVIX 10, regions Dfw) — same underlying entity. Entity identity vendor:router+russian — collapsed across regions (agents-036 Gate 3, <14d window).
Note addedby watchkeeperJul 16, 2026, 08:01 PM UTC
SEV1 candidate: multi-region OVIX 10 with fresh events. Held at SEV2 — requires human validation to promote to SEV1 (spec §2).
Note addedby watchkeeperJul 18, 2026, 12:30 AM UTC
SEV1 candidate: multi-region OVIX 10 with fresh events. Held at SEV2 — requires human validation to promote to SEV1 (spec §2).
Note addedby watchkeeperJul 19, 2026, 02:30 AM UTC
SEV1 candidate: multi-region OVIX 10 with fresh events. Held at SEV2 — requires human validation to promote to SEV1 (spec §2).
Note addedby watchkeeperJul 20, 2026, 04:00 AM UTC
SEV1 candidate: multi-region OVIX 10 with fresh events. Held at SEV2 — requires human validation to promote to SEV1 (spec §2).
Note addedby watchkeeperJul 20, 2026, 06:00 AM UTC
Merged new cluster (2 signals, OVIX 10, regions Denver) — same underlying entity. Entity identity vendor:operations+footprint — collapsed across regions (agents-036 Gate 3, <14d window).

Evidence / Why this?

Traced to source — read-onlyUpdated Jul 20, 06:00 AM UTC
Why declaredmergeDeterministic
Incident dedup / merge keys (entity, episode, network, region+title)v3
Checked in order against open same-domain incidents (never an aggregate-titled bucket): (1) ENTITY key, region-independent, incident active <14d (updated_at): shared CVE id, OR (cyber) >=2 shared distinctive vendor/product tokens (1 suffices when it carries a digit, i.e. a product model), OR (travel, agents-039) same travel operator/system key (travelSystemKey — airline/ATC/GDS/rail identity with a disruption cue), OR same network/AS key (agents-022). (2) EPISODE key (weather/environmental/disaster + travel per agents-039 + environmental air-quality per agents-040), incident active <7d: same hazard family (weather: heat/tornado/flood/cyclone/winter/wildfire/storm; travel: strike/ground_stop/airspace/it_outage/transit; environmental air-quality: air_quality/smoke — a multi-day wildfire-smoke wave, split cleanly from the weather wildfire FIRE family) AND same macro-region (eu | us/<census region> | country code) — a multi-day strike series, rolling ground stop, or smoke wave refreshes ONE incident, not dailies. (3) Legacy region-overlap + title-word dedup, active <24h (v5 unchanged). Merge unions affected_regions + related_signal_ids + material_event_keys, bumps event_count, advances the material clock, renders the merged regions into the description ("Affected regions:" trailer), logs stage=declare decision=merge (engine deterministic), and unions the evidence projection’s signal sources.
key
vendor:operations+footprint
via
entity
domain
cyber
regions
["Denver"]
signal ids
[32318,32323]
max severity
10
union regions
["Colorado Springs","Des Moines","Dfw","Denver"]
incident age h
0
Why SEV2SEV2score 2Deterministic
Incident severity level (SEV1–SEV4) at declarationv1
Base: SEV2 if sev>=9 AND news>=2 AND bpo>=1; else SEV3 if sev>=8 AND (news>=1 OR bpo>=1); else SEV4. Acute severe-weather (agents-028): if sev>=9 floor to SEV3 (SEV2→SEV3); minor/transient watches+advisories drop SEV2/SEV3→SEV4. Single-event cap: any SEV2 caps to SEV3 absent sustained multi-day BPO-region corroboration (SEV2 promotion is human-gated via revalidation). score = numeric SEV (1=most severe … 4); SEV3/SEV4 auto-validate, SEV1/SEV2 require human validation.
domain
cyber
bpo score
1
news score
3
persistent
yes
max severity
10
auto validated
no
acute weather floor
no
Geo Provenance
Tiercentroid
Sourcegeo_density
Deterministic
Sources✓ Corroborated · 5 sources
[Des Moines] cyber 10.0 — Improve Router Hygiene to Protect Against Russian State-Sponsored Targetingsentinel
US and allies warn of Russian critical infrastructure attacksbleepingcomputer.comThe US government warns that Russia state hackers are ...arstechnica.comImprove router hygiene to protect against Russian state-sponsored targetingncsc.govt.nz13 nations issue warning over Russian cyber targeting | CyberScoopcyberscoop.comRussian State Hackers Target Vulnerable Routers Worldwide - Infosecurity Magazineinfosecurity-magazine.com
[Colorado Springs] cyber 10.0 — Improve Router Hygiene to Protect Against Russian State-Sponsored Targetingsentinel
[Dfw] cyber 10.0 — Improve Router Hygiene to Protect Against Russian State-Sponsored Targetingsentinel
[Denver] cyber 10.0 — SALTO ProAccess Spacesentinel
[Denver] cyber 10.0 — AutomationDirect Productivity Suitesentinel

Related Signals20

[Des Moines] cyber 10.0 — AutomationDirect Productivity Suitesentinel12d ago[Colorado Springs] cyber 10.0 — AutomationDirect Productivity Suitesentinel12d ago[Denver] cyber 10.0 — AutomationDirect Productivity Suitesentinel12d ago[Dfw] cyber 10.0 — AutomationDirect Productivity Suitesentinel12d ago[Des Moines] cyber 10.0 — AutomationDirect Productivity Suitesentinel12d ago[Denver] cyber 10.0 — AutomationDirect Productivity Suitesentinel12d ago[Colorado Springs] cyber 10.0 — AutomationDirect Productivity Suitesentinel12d ago[Dfw] cyber 10.0 — AutomationDirect Productivity Suitesentinel12d ago[Des Moines] cyber 10.0 — SALTO ProAccess Spacesentinel12d ago[Denver] cyber 10.0 — SALTO ProAccess Spacesentinel12d ago[Colorado Springs] cyber 10.0 — SALTO ProAccess Spacesentinel12d ago[Dfw] cyber 10.0 — SALTO ProAccess Spacesentinel12d ago[Des Moines] cyber 10.0 — CISA Adds Four Known Exploited Vulnerabilities to Catalogsentinel12d ago[Dfw] cyber 10.0 — CISA Adds Four Known Exploited Vulnerabilities to Catalogsentinel12d ago[Colorado Springs] cyber 10.0 — CISA Adds Four Known Exploited Vulnerabilities to Catalogsentinel12d ago[Colorado Springs] cyber 10.0 — NASA Core Flight System (cFS) Health &amp; Safety (HS) Applicationsentinel12d ago[Des Moines] cyber 10.0 — NASA Core Flight System (cFS) Health &amp; Safety (HS) Applicationsentinel12d ago[Dfw] cyber 10.0 — NASA Core Flight System (cFS) Health &amp; Safety (HS) Applicationsentinel12d ago[Des Moines] cyber 10.0 — AutomationDirect Productivity Suitesentinel12d ago[Colorado Springs] cyber 10.0 — Improve Router Hygiene to Protect Against Russian State-Sponsored Targetingsentinel12d ago

External Corroboration

✓ Corroborated · 5 sourcesChecked Jul 14, 2026, 03:00 PM UTC
US and allies warn of Russian critical infrastructure attacksbleepingcomputer.comJul 13, 2026, 12:00 AM UTCThe US government warns that Russia state hackers are ...arstechnica.comJul 13, 2026, 09:00 PM UTCImprove router hygiene to protect against Russian state-sponsored targetingncsc.govt.nzJul 13, 2026, 10:15 PM UTC13 nations issue warning over Russian cyber targeting | CyberScoopcyberscoop.comJul 13, 2026, 03:23 PM UTCRussian State Hackers Target Vulnerable Routers Worldwide - Infosecurity Magazineinfosecurity-magazine.comJul 13, 2026, 09:40 AM UTC

Affected Regions

Colorado SpringsDenverDes MoinesDfw