Monday , September 7 2026
MikroTik

Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

Attackers are misusing MikroTik routers through their Secure Shell (SSH) service, which can be accessed from the internet, to take full control without logging in, as per CERT Polska’s warning released on September 5.

Successful attacks started on at least September 2. The Hacker News review on September 6 found no number of victims or who the attacker was. MikroTik’s security update shows updated RouterOS versions. CERT says these updates stop the attacks seen and suggests installing them right away, then checking for any changes in the setup.

Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

Attackers are misusing MikroTik routers through their Secure Shell (SSH) service, which can be accessed from the internet, to take...
Read More
Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

CrowdStrike launched CrowdStrike SafeMind, a set of special security models and tools from the CrowdStrike Cyber Superintelligence Lab. The SafeMind...
Read More
CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

Chinese-speaking hackers have added Claude, Qwen, and DeepSeek to their hacking system to automate cyberattacks on governments and other targets...
Read More
Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

India: C-DOT Launches 14 Local Quantum-Safe Technologies

India is making its communication systems safer and stronger by launching 14 local quantum products. These products were made by...
Read More
India: C-DOT Launches 14 Local Quantum-Safe Technologies

14,000 Dahua cameras compromised: TP-Link flaws enable RCE

Over 14,000 Dahua security cameras connected to the internet have been hacked in a 35-day online attack that affected devices...
Read More
14,000 Dahua cameras compromised: TP-Link flaws enable RCE

Microsoft Reveals Project Zenith Windows PCs Able to Run 30B+ AI Models Locally

Microsoft has launched Project Zenith, a new Windows 11 experience for developers. It is made for powerful PCs that can...
Read More
Microsoft Reveals Project Zenith Windows PCs Able to Run 30B+ AI Models Locally

Google issues warning of new Chrome zero-day flaw exploited

Google has updated the Chrome browser to fix a serious security issue in the V8 engine and 11 other flaws....
Read More
Google issues warning of new Chrome zero-day flaw exploited

CrowdStrike’s ‘FalconFlank’ zero-day allows SYSTEM privileges

An unnamed security expert known as "Nightmare Eclipse" shared a CrowdStrike Falcon zero-day exploit called "FalconFlank." This tool allows hackers...
Read More
CrowdStrike’s ‘FalconFlank’ zero-day allows SYSTEM privileges

727,000 data exposes: French hospital fined €500,000

France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for not properly protecting the data...
Read More
727,000 data exposes: French hospital fined €500,000

153 Million Driver’s License Surfaced on Dark Web: FBI Starts Investigation

The FBI’s New Orleans field office has opened an investigation into the suspected source of more than 153 million driver’s...
Read More
153 Million Driver’s License Surfaced on Dark Web: FBI Starts Investigation

Home MikroTik devices block public access to management ports. Their default firewall rules stay the same, according to the vendor’s explanation.

Affected range reported by CERT Initial security fix Update guidance
From 6.0.0 below 6.49.21 6.49.21 RouterOS 6 security release
From 7.0.0 below 7.23.4 7.23.4 Use 7.23.5 on the long-term channel
From 7.24 below 7.24.2 7.24.2 Stable channel security release
No development range listed in CERT’s disclosure 7.25beta3 Development channel fix

The 7.23.5 fix solves an IPv6 DHCP problem that came with 7.23.4 and keeps the security update. Until the fix is installed, CERT suggests turning off open services or limiting access to trusted networks, especially for SSH, WWW/WWW-SSL, and bandwidth-test.

It warns not to start Transport Layer Security (TLS) connections or use RouterOS’s built-in SSH clients from a device that is not updated. These temporary rules address a wider range of issues and do not replace the update.

MikroTik’s Flagged status guidance says that RouterOS marks a device when it finds a strange setup during start checks. RouterOS turns off those settings and limits some functions.

After updating, look at the logs and run /system/device-mode/print to check the status. Even without a warning, check the settings for unknown users, scripts, and other changes that are not recognized.

CERT also highlights unusual high-level operation accounts and account creation logs that include ssh:-2@ as clues for investigation.

If the warning, logs, or configuration suggest compromise, CERT recommends these recovery steps. Do not clear Flagged before preserving the evidence and completing the analysis.

Isolate the router from the network and preserve its logs and configuration before resetting it. CERT’s preservation guide in Polish explains how to export and download the files.
Restore factory settings and rebuild using a trusted, verified configuration. Do not blindly restore a full backup from the potentially compromised device.
Change passwords, keys and other secrets in use.

CERT calls the reported 2-flaw combination MikroTrick. The Hacker News compared CERT’s warning and vulnerability disclosure on September 6. Neither explicitly identifies which 2 vulnerabilities form the observed chain or explains how they combine to give administrative control.

The 7.25beta3 release notes have a September 2 changelog date, while the beta and other initial fixes were announced on September 3. The Hacker News compared these release announcements with CERT’s attack timeline on September 6. Those dates do not establish whether a fix was publicly available before the attacks, so zero-day status remains unverified.

Check Also

Microsoft Exchange Server

CVE-2026-62911
Nearly 22,000 Microsoft Exchange Servers are vulnerable to attack

Almost 22,000 Microsoft Exchange servers are online and still vulnerable to a flaw that lets …