hacker-news · Crawled Sep 6, 2026
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Read original article ↗AI Summary
Attackers are exploiting a vulnerability chain in MikroTik RouterOS, dubbed 'MikroTrick' by CERT Polska, to gain full administrative control of internet-exposed routers via SSH without authentication. The attacks, observed since at least September 2, 2026, target unpatched devices across multiple RouterOS versions. CERT recommends immediate updates to fixed firmware versions, as temporary mitigations include disabling exposed management services and avoiding use of built-in clients from unpatched systems. Evidence of compromise includes unexpected privileged accounts and specific SSH login logs.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.