Saturday , September 26 2026
MikroTik

Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

Attackers are misusing MikroTik routers through their Secure Shell (SSH) service, which can be accessed from the internet, to take full control without logging in, as per CERT Polska’s warning released on September 5.

Successful attacks started on at least September 2. The Hacker News review on September 6 found no number of victims or who the attacker was. MikroTik’s security update shows updated RouterOS versions. CERT says these updates stop the attacks seen and suggests installing them right away, then checking for any changes in the setup.

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Home MikroTik devices block public access to management ports. Their default firewall rules stay the same, according to the vendor’s explanation.

Affected range reported by CERT Initial security fix Update guidance
From 6.0.0 below 6.49.21 6.49.21 RouterOS 6 security release
From 7.0.0 below 7.23.4 7.23.4 Use 7.23.5 on the long-term channel
From 7.24 below 7.24.2 7.24.2 Stable channel security release
No development range listed in CERT’s disclosure 7.25beta3 Development channel fix

The 7.23.5 fix solves an IPv6 DHCP problem that came with 7.23.4 and keeps the security update. Until the fix is installed, CERT suggests turning off open services or limiting access to trusted networks, especially for SSH, WWW/WWW-SSL, and bandwidth-test.

It warns not to start Transport Layer Security (TLS) connections or use RouterOS’s built-in SSH clients from a device that is not updated. These temporary rules address a wider range of issues and do not replace the update.

MikroTik’s Flagged status guidance says that RouterOS marks a device when it finds a strange setup during start checks. RouterOS turns off those settings and limits some functions.

After updating, look at the logs and run /system/device-mode/print to check the status. Even without a warning, check the settings for unknown users, scripts, and other changes that are not recognized.

CERT also highlights unusual high-level operation accounts and account creation logs that include ssh:-2@ as clues for investigation.

If the warning, logs, or configuration suggest compromise, CERT recommends these recovery steps. Do not clear Flagged before preserving the evidence and completing the analysis.

Isolate the router from the network and preserve its logs and configuration before resetting it. CERT’s preservation guide in Polish explains how to export and download the files.
Restore factory settings and rebuild using a trusted, verified configuration. Do not blindly restore a full backup from the potentially compromised device.
Change passwords, keys and other secrets in use.

CERT calls the reported 2-flaw combination MikroTrick. The Hacker News compared CERT’s warning and vulnerability disclosure on September 6. Neither explicitly identifies which 2 vulnerabilities form the observed chain or explains how they combine to give administrative control.

The 7.25beta3 release notes have a September 2 changelog date, while the beta and other initial fixes were announced on September 3. The Hacker News compared these release announcements with CERT’s attack timeline on September 6. Those dates do not establish whether a fix was publicly available before the attacks, so zero-day status remains unverified.

Check Also

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could …