Close Menu
NCIJ Network NCIJ Network
    What's Hot

    My Brief Summer Fling With Siri AI

    September 6, 2026

    Attackers conceal phishing lures using invisible Unicode characters

    September 6, 2026

    600 BTC Mined in 2010 Moves After 16 Years of Dormancy

    September 6, 2026
    Facebook X (Twitter) Instagram
    Trending
    • My Brief Summer Fling With Siri AI
    • Attackers conceal phishing lures using invisible Unicode characters
    • 600 BTC Mined in 2010 Moves After 16 Years of Dormancy
    • US envoys meet Putin: What’s behind latest diplomacy on Russia-Ukraine war? | Russia-Ukraine war News
    • Trump Administration Again Asks Supreme Court to Allow Mail Voting Restrictions
    • Competitive Pokémon is on phones now, but you still need a Switch to become a champion
    • Solana ETF inflows fall 97% as CME net shorts shrink
    • Some joints may be primed for rheumatoid arthritis before birth
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, September 6
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 6, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalSep 06, 2026Vulnerability / Network Security

    Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska’s attack warning, published on September 5.

    Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count or attacker identity.

    MikroTik’s security update lists fixed RouterOS releases. CERT says the fixes prevent the observed attacks and recommends immediate installation, followed by a check for unauthorized configuration changes.

    According to the vendor’s default firewall explanation, home MikroTik devices block public access to management ports while their default firewall rules remain intact.

    Cybersecurity

    The Hacker News checked CERT’s affected RouterOS versions against MikroTik’s listed fixes on September 6. Use the official RouterOS downloads for your update.

    Affected range reported by CERT Initial security fix Update guidance
    From 6.0.0 below 6.49.21 6.49.21 RouterOS 6 security release
    From 7.0.0 below 7.23.4 7.23.4 Use 7.23.5 on the long-term channel
    From 7.24 below 7.24.2 7.24.2 Stable channel security release
    No development range listed in CERT’s disclosure 7.25beta3 Development channel fix

    The 7.23.5 regression fix addresses an IPv6 DHCP (Dynamic Host Configuration Protocol) problem introduced in 7.23.4 while retaining the security update.

    Until the update can be installed, CERT recommends turning off exposed services or restricting access to trusted management networks, particularly for SSH, WWW/WWW-SSL, and bandwidth-test.

    It also advises against initiating Transport Layer Security (TLS) connections or using RouterOS’s built-in SSH clients from an unpatched device. These temporary restrictions cover the broader set of vulnerabilities and do not replace the update.

    MikroTik’s Flagged status guidance states that RouterOS flags a device when startup checks detect suspicious configuration. RouterOS disables those entries and restricts certain functions.

    After updating, check the logs and run /system/device-mode/print to inspect that status. Even without a warning, inspect the configuration for unknown users, scripts, and other unrecognized changes.

    CERT also points to unexpected highly privileged ops accounts and account-creation logs containing ssh:-2@ as signs to investigate.

    Cybersecurity

    If the warning, logs, or configuration suggest compromise, CERT recommends these recovery steps. Do not clear Flagged before preserving the evidence and completing the analysis.

    1. Isolate the router from the network and preserve its logs and configuration before resetting it. CERT’s preservation guide in Polish explains how to export and download the files.
    2. Restore factory settings and rebuild using a trusted, verified configuration. Do not blindly restore a full backup from the potentially compromised device.
    3. Change passwords, keys and other secrets in use.

    CERT calls the reported 2-flaw combination MikroTrick. The Hacker News compared CERT’s warning and vulnerability disclosure on September 6. Neither explicitly identifies which 2 vulnerabilities form the observed chain or explains how they combine to give administrative control.

    The 7.25beta3 release notes have a September 2 changelog date, while the beta and other initial fixes were announced on September 3. The Hacker News compared these release announcements with CERT’s attack timeline on September 6. Those dates do not establish whether a fix was publicly available before the attacks, so zero-day status remains unverified.

    The Hacker News has contacted CERT Polska and MikroTik for comment.

    Attackers Authentication hijack InternetExposed MikroTik routers SSH
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Attackers conceal phishing lures using invisible Unicode characters

    Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

    Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

    Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

    Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers’ Data It Said Was Deleted

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    My Brief Summer Fling With Siri AI

    September 6, 2026

    Attackers conceal phishing lures using invisible Unicode characters

    September 6, 2026

    600 BTC Mined in 2010 Moves After 16 Years of Dormancy

    September 6, 2026

    US envoys meet Putin: What’s behind latest diplomacy on Russia-Ukraine war? | Russia-Ukraine war News

    September 6, 2026
    Latest Posts

    Quantum computing nears commercial breakthrough, IBM CEO says

    August 1, 2026

    Amgen says cloud data breach exposed patient health, proprietary info

    August 1, 2026

    Snapchat joins other platforms in the fight against ‘AI slop’

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    My Brief Summer Fling With Siri AI

    September 6, 2026

    Attackers conceal phishing lures using invisible Unicode characters

    September 6, 2026

    600 BTC Mined in 2010 Moves After 16 Years of Dormancy

    September 6, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.