How To Fix Your Router's Security Stinks

The Cyber Security Review | Thursday, June 30, 2022

Incapacitate remote administrative access, and disable administrative access over wifi. Administrators should bind to routers through wired Ethernet only.

Fremont, CA: Most wifi routers and network gateways home customers use are not secure. A security expert said that some are so vulnerable to attack that they should be thrown out at the HOPE X hacker conference in New York.

Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.

"If a router is sold at, you don't want to buy it," self-sufficient computer consultant Michael Horowitz told the audience.

"If your router is given by their internet service provider [ISP], they don't want to use it either, because they give away millions of them, and that makes them a prime target both for spy agencies and bad guys," he added

Horowitz recommended that security-conscious consumers upgrade to commercial routers for small businesses or at least separate their modems and routers into two separate devices. (Many "gateway" units can act as both, often supplied by ISPs.) Failing one of those options, Horowitz gave a record of precautions users could take.

Problems with consumer routers

Routers are the vital but unexpected workhorses of modern computer networking. Yet few home users understand routers are, in fact, full-fledged computers with their operating systems, software, and susceptibilities.

Horowitz said, "A compromised router can spy on you," explaining that a router under an attacker's control can stage a man-in-the-middle attack, alter unencrypted data or send the user to "evil twin" websites masquerading as often-used webmail or online-banking portals.

Horowitz noted that many consumer-grade home-gateway devices fail to notify users if and when firmware updates become available, even though those updates are essential to patch security holes. In addition, other devices will not accept passwords longer than 16 characters — the minimum length for password safety today.

Universal Pwn and Play

Millions of routers worldwide, even some of the best ones, have the Universal Plug and Play (UPnP) networking protocol enabled on internet-facing ports, which exposes them to external attacks.

Horowitz said, "UPnP was designed for local area networks [LANs], and as such, it has no security. So in and of itself, it's not such a big deal." Still, he added, "UPnP on the internet is like going in for surgery and having the doctor work on the wrong leg."

Another issue is the Home Network Administration Protocol (HNAP), a management tool found on some older consumer-grade routers that transmit sensitive information about the router over the Web at HTTP://[router IP address]/HNAP1/and gives full control to remote users who provide administrative usernames and passwords.

Easy fixes for your home wireless router

Alter the administrative credentials from the default username and password. They are the first things an attacker will try. Your router's instruction manual should guide you on how to do this. If not, then Google it.

Make the password long, strong and different, and don't make it anything resembling the usual password to access the wifi network.

Rename the network name, or SSID, from "Netgear," "Linksys," or whatever the default is to something special — but don't give it a name that identifies you.

"If you stay in an apartment building in apartment 3G, don't call your SSID 'Apartment 3G,'" Horowitz quipped. "Call it 'Apartment 5F.'"

Turn on automatic firmware modernizes if they're ready. Newer routers, comprising most mesh routers, will automatically update the router firmware.

Enable WPA2 wireless encryption so only authorized users can hop on your network. If your router helps only the old WEP standard, it's time for a new router.

Allow the new WPA3 encryption standard if the router supports it. However, as of mid-2021, only the latest routers and client devices, for example, PCs, mobile devices, and smart-home devices, do.

Disable wifi Protected Setup if your router lets you.

Set up a guest wifi network and offer its use to visitors if your router has such a feature. Preferably, set the guest network to turn itself off after a set period.

"You can change on your guest network and set a timer, and three hours later, it turns itself off," Horowitz said. "That's a nice security feature."

If you have many smart-home or Internet of Things devices, many won't be secure. So connect them to your guest wifi network instead of your primary network to minimize the damage resulting from any potential bargain of an IoT device.

Don't use cloud-based router management if your router's manufacturer gives it. Alternatively, figure out if you can turn that feature off.

Horowitz said, "This is a really bad idea. If your router offers that, I wouldn't do it, due to now you're trusting another person between you and your router."

Many "mesh router" systems, like Nest wifi and Eero, are entirely cloud-dependent and can interface with the user only through cloud-based smartphone apps.

While those models provide security improvements in other areas, such as with automatic firmware updates, it might be worth looking for a mesh-style router that permits local administrative access, such as the Netgear Orbi.

Moderately tough home router fixes

Install new firmware when it turns available. This way, router makers install security patches. Then, log into your router's administrative interface regularly to check — here's a guide with more information.

You may have to control the manufacturer's website for firmware advances with some brands. Yet have a backup router on hand if something deviates. Some routers also permit you back up the current firmware before installing an update.

Incapacitate remote administrative access, and disable administrative access over wifi. Administrators should bind to routers through wired Ethernet only.

More in News

Businesses of all kinds, corporations, organizations, and even governments have used computerized technology to improve their day-to-day operations. As a result, addressing cybersecurity has become crucial in protecting data from numerous online threats and unlawful access. With the advent of technology, cybersecurity trends have evolved, with data breaches, ransomware attacks, and hacking incidents becoming more common. Enroll in security courses taught by industry experts to improve your expertise and equip yourself with the information and skills required for comprehensive data protection. Top Cybersecurity Trends Out of many cybersecurity, some of them are: The Emergence of Automotive Cybersecurity Threats: Modern vehicles have advanced software that provides seamless connectivity and features like cruise control, engine timing, and driver assistance systems. Nevertheless, this dependence on automation and connectivity makes vehicles vulnerable to hacking threats. By using communication technologies such as Bluetooth and WiFi, hackers can take advantage of weaknesses to manipulate the car or listen in on conversations using the built-in microphones. As the use of automated vehicles continues to grow, these risks are anticipated to increase, highlighting the need for strict cybersecurity protocols, especially for self-driving or autonomous cars. Utilizing the Power of Artificial Intelligence in Cybersecurity: AI plays a vital part in strengthening cybersecurity in different industries. By using machine learning algorithms, AI has made it possible to create automated security systems that can perform tasks such as natural language processing, face detection, and threat detection. Nevertheless, cybercriminals also use this technology to develop advanced attacks that bypass security measures. Despite these difficulties, AI-powered threat detection systems can quickly respond to new threats, offering substantial assistance to cybersecurity experts. Mobile Devices: Target for Cyber Attacks Mobile device usage has attracted cybercriminals, leading to a surge in malware and cyberattacks aimed at mobile banking and personal information. The widespread reliance on smartphones for tasks such as financial transactions and communication heightens the vulnerability to potential security breaches. Cloud Security Challenges and Solutions: Organizations must prioritize strong security measures when utilizing cloud data storage and operations services. Despite cloud providers implementing robust security protocols, vulnerabilities can still occur due to user errors, malware, or phishing attempts. Consistent monitoring and updates are necessary to minimize risks and protect sensitive data stored in the cloud. ...Read more
Artificial intelligence (AI) is rapidly transforming the cybersecurity landscape, bringing novel techniques to safeguarding digital assets and combatting emerging threats. The following shows the key ways that AI is affecting. cybersecurity:  Advanced threat detection:  AI systems are particularly good at seeing odd patterns, which makes it possible to identify possible cyber threats early on. These dangers can include malware and highly skilled phishing attacks. Huge volumes of data, including network traffic, can be analyzed by AI algorithms, which can then be used to identify odd patterns that can point to a security breach. This feature makes it possible to identify advanced persistent threats (APTs) and zero-day attacks early on that more conventional security procedures would overlook. Because AI is capable of continual learning, these systems improve with time and can adapt to new and changing threats. This proactive approach to threat identification is essential in today's ever-evolving cybersecurity landscape. Predictive risk analysis:  Predictive analytics is the application of AI to predict possible security breaches. By processing large volumes of data and identifying patterns that may indicate future security risks, AI helps businesses proactively reinforce their defenses. AI solutions can proactively fortify the organization's defenses by employing machine learning algorithms to predict possible weaknesses and security breaches. In the ever-changing field of cybersecurity, where staying ahead of potential threats is critical to preserving strong security measures, this predictive power is invaluable. User behavior analytics:  AI examines user behavior to find compromised accounts or possible insider threats. Through the use of user behavior analytics (UBA) in cybersecurity, AI may utilize sophisticated machine learning algorithms to examine user behavior and identify irregularities. Through the identification of actions that differ from known patterns, this research aids in the identification of potential security issues, such as hacked accounts or insider threats. These systems can adjust to new patterns in user behavior thanks to AI's capacity for continual learning, which gradually improves their accuracy. Because of this, AI is a priceless tool that enables a more dynamic and sophisticated method of monitoring and protecting networks from user-related threats. Fraud detection:  AI systems are essential for identifying and stopping fraudulent activity in e-commerce and online transactions, which is implemented by, Real-time processing:  AI provides real-time transaction analysis, enabling prompt fraud identification and prevention. Pattern recognition:  AI algorithms are excellent at finding patterns and abnormalities in transaction data, which can be used to identify fraud. ...Read more
In today’s rapidly evolving digital landscape, operational technology (OT) and information technology (IT) are increasingly intertwined. As industrial environments adopt more connected systems, integrating traditional OT infrastructure such as control systems, sensors, and industrial networks with IT has become both a technological opportunity and a cybersecurity challenge. Converged OT cybersecurity emerges as an essential strategy, merging the defensive capabilities of IT security with the unique requirements of OT systems. Organizations achieve a unified, robust approach to protect critical infrastructure, ensure operational continuity, and enhance overall business resilience. Enhanced Operational Resilience and Threat Detection Converged OT cybersecurity greatly enhances operational resilience by unifying the defense mechanisms across disparate systems. OT and IT security teams managed their networks independently, often resulting in gaps exploited by sophisticated cyber threats. With converged cybersecurity solutions, organizations employ a single, cohesive strategy that provides holistic protection. Integrated platforms enable continuous monitoring across both IT and OT systems, allowing security teams to detect anomalies and potential breaches in real time. The rapid detection capability enables faster response, minimizes downtime, and protects critical processes in manufacturing, energy, and transportation sectors. Converged platforms draw insights from a diverse range of sources, leveraging AI and ML to identify patterns that may indicate emerging threats. The platforms continuously update security models based on evolving attack methodologies, ensuring that both operational and business systems remain resilient. When a danger targets sensitive OT components, early detection and automated response protect the physical equipment and safeguard the interconnected business systems that depend on them. Streamlined Management and Regulatory Compliance Integrating OT and IT security reduces the complexity associated with managing two disparate systems. Organizations now enjoy centralized control through unified dashboards that present a consolidated view of security postures across all systems. The streamlining reduces overhead, improves resource allocation, and facilitates quicker decision-making when addressing vulnerabilities or responding to incidents. With all security events captured in a single platform, IT and OT teams can collaborate more effectively and share insights that were previously siloed. Converged OT cybersecurity represents a strategic evolution in protecting modern industrial environments. Regulatory compliance also improves under a converged framework. Stringent cybersecurity standards and operational regulations govern industries such as energy, healthcare, and transportation. Unified cybersecurity solutions help organizations meet these demands by enforcing consistent security policies and maintaining comprehensive logs for audits. Automated compliance reporting, built into many converged platforms, reduces the manual burden on IT and operations staff while ensuring that documentation is always up to date. The integrated approach minimizes the risk of legal penalties and helps build stakeholder trust, demonstrating a commitment to secure, responsible management of critical infrastructure. ...Read more
Cybersecurity leaders are confronting a threat surface that no longer stops at networks, applications or cloud infrastructure. Public narratives now shape market trust, employee safety and financial stability at a speed and scale traditional controls were never designed to manage. Disinformation campaigns can erode confidence through coordinated social activity, impersonation, manipulated media and poisoned search or language model outputs, often faster than incident response teams can react. For executives accountable for enterprise risk, this shift creates a gap between technical security programs and the reputational and behavioral forces that increasingly determine impact. Recent incidents have demonstrated how rapidly online narratives can trigger stock volatility, executive targeting or consumer backlash without breaching a single internal system. Social platforms, open media channels and generative systems have become an externalized attack surface where intent is obscured, attribution is difficult and volume overwhelms manual review. In regulated or trust-dependent industries such as finance, energy or healthcare, the consequences extend beyond brand damage into systemic risk. Responsibility for this domain often falls between communications, legal and security teams, leaving fragmented ownership at the moment coordination matters most. What distinguishes effective approaches in this environment is the ability to interpret meaning rather than signals alone. Monitoring volume, keywords or engagement provides limited insight once adversaries adapt language, tone or cultural framing. Mature programs instead focus on understanding what is being said, why it matters and how quickly it may cross a threshold where intervention loses effectiveness. This requires early detection across languages and platforms, discrimination between noise and credible threat and a path from analysis to action that aligns with security decision-making rather than marketing response. Within this emerging discipline, B rinker stands out for grounding narrative intelligence directly inside the cybersecurity risk model. Its platform is designed to analyze full conversations across open online spaces, identifying harmful narratives based on intent, context and propagation rather than surface indicators. By interpreting euphemism, irony and coordinated framing, it enables security teams to recognize disinformation and manipulation while mitigation is still feasible. The system traces narrative origin, language distribution and platform dynamics, providing clarity on how and where a threat is forming. Beyond detection, Brinker connects analysis to response. The platform supports automated takedown requests, legal documentation preparation and stakeholder communication workflows while also advising counter-narratives informed by behavioral psychology rather than factual rebuttal alone. Its reach extends into emerging channels where enterprises are increasingly evaluated, including large language model outputs that can be influenced by persistent misinformation. The technology is built to operate across languages and platforms at scale, addressing cost constraints through optimized model orchestration that limits false positives without prohibitive processing expense. This combination of narrative comprehension, early warning and integrated mitigation reflects a security mindset applied to an environment that has historically been treated as peripheral. It recognizes that once harmful narratives reach mass adoption, control diminishes sharply. Preventing escalation depends on speed, contextual understanding and disciplined response, qualities familiar to cybersecurity teams but newly applied to public discourse risk. For organizations seeking a credible standard in narrative intelligence, Brinker represents a compelling choice. Its focus on intent-driven analysis, cross-platform visibility and actionable mitigation aligns with how modern cyber risk now manifests outside the firewall. For executives tasked with protecting trust, continuity and stability, it offers a structured way to bring narrative risk into the core security program rather than leaving it to chance or fragmented ownership. ...Read more