'When it rains, it pours' (news, anyway). From
PC Magazine April 7, 2026:
Are You Using These TP-Link Routers? Russian Hackers Are Targeting Them
From the article:
"A Russian state-sponsored hacking group has been targeting vulnerable consumer
Wi-Fi routers, including 23 TP-Link models, some of which have reached "end of life" status.
The threat involves
Fancy Bear, also known as APT 28, a notorious hacking group affiliated with Russian military intelligence. On Tuesday, Microsoft and the UK’s National Cyber Security Centre (NCSC) said the group has been hacking vulnerable routers to manipulate internet traffic and harvest login information.
“Microsoft Threat Intelligence has identified over 200 organizations and 5,000 consumer devices" that have been under attack since at least August, the company
warned."
It notes many of those models were released over a decade ago, and that in recent times TP-Link has moved to auto-updating firmware, but that appeared to only apply to newer Archer models. Ironically, the recent ban, if nothing changes, will stop future firmware updates beyond a set date.
---------------
Putting aside TP-Link's misfortune (with old, outdated hardware) at a particularly inopportune time, here's something of interest from the article:
"The US's Justice Department is also
calling on users to "Replace End-of-Life and End-of-Support routers.""
This raises multiple issues/questions for consumer router users.
1.) Most users aren't networking or even computing enthusiasts and 'set it and forget it,' and stick with old gear thinking '
if it ain't broke, don't fix it,' if they think about it at all. How many know what firmware is, and how many of those know or care about updating it? How many know about WPA 2 vs. 3 and similar security concerns?
2.)
So TP-Link now auto-updates firmware; great! Do Netgear, Amazon's Eero, ASUS, etc.? Should this be mandatory?
3.)
How does the average home internet router user know his router is 'end of life' or 'end of support?' Is there a set number of years where routers are supposed to be replaced? Does this vary by brand?
4.) How credible is it to expect the big majority of people to do this? I see online it's recommended to replace our surge protectors every 3-5 years; how many of you do that? How many of us use Macs that are no longer eligible for security updates?
5.) What about 'Internet of Things' devices? I've seen elsewhere some consider them threats not unlike routers, and at least some may be subject to firmware updates that could contain malware.
Do we need to be worried about our IoT devices reaching 'end of life' or 'end of support?' Does it matter what that device's function is? I guess if the Chinese Communist Party or the Russians can flip my kid's Alexa-controlled ceiling light on and off they can annoy us...but what about her Echo Show?
6.)
What do you think (i.e.: 'how do you feel') about forced obsolescence, making routers automatically stop functioning after a pre-determined interval, or require them to have ongoing authorization from some central authority (e.g.: the FCC) that can 'pull the plug' on models deemed insecure?
7.)
Do you foresee anti-virus/anti-malware/security software packages like BitDefender and Norton (a quick Search online shows mention of 'BitDefender Router Protection' and 'NetGear Armor'),
stepping up to deal with this? Will it be a separate product? How technically feasible is it for such a product to make an outdated, otherwise unsupported old router safe to us?