Search/82.192.72.4
IOC

82.192.72.4

Type
IP
Source
News extraction
First seen
Sep 7, 2026
Last seen
Sep 8, 2026
Look up on VirusTotal
Connections
4 relationships
MikroTik Patches Critical Flaws Chained to Hack Routers
Network equipment maker MikroTik has rolled out patches for six vulnerabilities in RouterOS, urging users to apply them as soon as possible, as two of them have been flagged as exploited. The exploited flaws, dubbed MikroTrick, allow attackers to bypass authentication and take over devices, CERT Poland warns. In a scarce advisory, MikroTik warns of the identified security defects, recommends immediate patching, and directs users to CERT Poland’s advisory for additional information. “This is an important security update. Most configurations are not at risk,” MikroTik says. It also recommends blocking SSH access from untrusted sources, noting that compromised devices will have a “Flagged” entry in the log section. CERT Poland, meanwhile, says it has received confirmation that two of the resolved vulnerabilities have been chained together to compromise devices. “We now have confirmation that the combination of two of them (MikroTrick) is being exploited to take full control of devices whose SSH service is accessible from public networks. According to the information we have, updating to the latest version prevents these attacks,” CERT Poland notes. It highlights three vulnerabilities: CVE-2026-67276 (CVSS score of 9.2), an SSH authentication bypass bug; CVE-2026-86060 (CVSS score of 9.2), an SSH session privilege manipulation issue; and CVE-2026-67277 (CVSS score of 8.8), a memory disclosure and denial-of-service weakness. CERT Poland says hackers have been chaining the MikroTrick bugs since at least September 2, creating an account named ‘ops’. The attacks have been originating from two IP addresses, namely 82.192.72.4 and 103.102.31.18. “The presence of any of these artifacts indicates an attempt to exploit the vulnerabilities and must be investigated immediately; at the same time, the absence of the traces mentioned above does not rule out unauthorized activity,” CERT Poland notes. Users are advised to update their MikroTik routers to RouterOS versions 7.25beta3, 7.24.2, 7.23.4, or 6.49.21 as soon as possible. The updates also resolve CVE-2026-67278 (enables TLS server impersonation), CVE-2026-67279 (allows unauthenticated attackers to tamper with files, including configuration files), and CVE-2026-67281 (allows attackers to disclose root-owned files, including configuration stores). The Shadowserver Foundation found more than 120,000 MikroTik devices with SSH accessible from the internet during a 24-hour scan window on September 5. Related: Adobe Commerce Zero-Day Exploited to Backdoor Online Stores Related: HPE Patches Critical RCE Vulnerabilities in AOS-CX Related: Malicious Virtualizor Update Served via BGP Hijacking
securityweek.comSep 8, 2026extracted
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management gave outsiders useful clues before login. Add active attacks on browsers, routers, and online stores, and there’s plenty to check—even for teams that have kept up with the patches. Read the full recap for the week’s major developments, plus more research, attacks, and security news beyond what we covered last week. ⚡ Threat of the Week N-able Patches Critical N-central Flaws — N-able has released hotfixes to address two severe N-central flaws (CVE-2026-86206 and CVE-2026-86207) that could allow an unauthorized party to bypass authentication controls and gain full access to the platform. Also patched is a maximum-severity security flaw (CVE-2026-86218, CVSS score: 10.0) that could allow for pre-authenticated remote code execution on the N-central server. "At this time, we have no confirmation that these vulnerabilities have been exploited in production environments, but unpatched systems remain at risk," N-able said. However, Huntress said it observed signs that attackers are likely leveraging CVE-2026-86206 or/and CVE-2026-86207, after it launched an investigation on September 4 following the compromise of a customer's fully patched N-central production environment. "However, due to limited historical logging available directly on the appliance, we cannot definitively confirm which specific exploit the threat actor used to achieve their compromise, nor can we rule out the use of alternative vulnerabilities," it said. AI Spend Out of Control? There's a Path Forward Imagine you’ve received a water bill for 500,000,000 gallons. Now, you have to account for every teaspoon of that water. IT leaders face a similar task when managing AI budgets, and it’s not as simple as token caps or model limits. Learn how your team can optimize your company's AI spend. Learn More ➝ 🔔 Top News Google Warns of Chrome 0-Day Under Attack — Google released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," according to a description of the flaw in CVE.org. Security researcher Salvatore Gulizia (aka Serotav) has been credited with discovering and reporting the flaw on August 4, 2026. As is usual in these cases, Google acknowledged that an "exploit for CVE-2026-85046 exists in the wild," but did not reveal any details about the nature of the attacks or who is behind them. With the latest development, Google has addressed a total of six actively exploited Chrome zero-days since the start of the year. MikroTik RouterOS Flaws Exploited — The CERT Polska Team warned that bad actors are actively exploiting two zero-day flaws in MikroTik RouterOS that could be combined to take full control of the device without authentication if the device supports remote access using the SSH protocol. The exploit chain has been codenamed MikroTrick. A total of fix flaws (CVE-2026-67276, CVE-2026-67277, CVE-2026-67278, CVE-2026-67279, CVE-2026-67281, and CVE-2026-86060) have been identified. The MikroTrick chain involves CVE-2026-67276 and CVE-2026-86060 (CVSS scores: 9.2), which can allow an attacker to bypass authentication and elevate their privileges. The issues have been fixed in versions 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable). "The successful attacks observed so far, including the creation of the 'ops' account, originated from the IP address 82.192.72.4 and have been occurring since at least 2 September," CERT Polska said. "In addition, the IP address 103.102.31.18 was used in attempts to exploit the described chain." Unpatched Magento and Adobe Commerce 0-Day Exploited to Backdoor Online Stores — E-commerce storefronts are being compromised to inject a backdoor by exploiting an unpatched Magento and Adobe Commerce zero-day dubbed StyleSmuggler, which gives unauthenticated attackers remote code execution. The attacks commenced on September 4, 2026. "StyleSmuggler injects malicious code into Magento's template system," Sansec said. "By using the styles properties, it can evade existing safeguards. It works in two stages: (1) Inject (poison) PHP code, for example by generating a failure report, and (2) Let Magento execute the poisoned code via a failed payment email." The backdoor is a Rust program that connects to the "99.84.67[.]186" C2 server and waits for further instructions. There are currently no indications that the backdoor has been weaponized. There are two different variants named fc-cache and chronyd. A separate attack cluster has been found to leverage the same weakness to drop a PHP web shell into the product image cache. RevStealer Spreads via Game Cheats and Fake Claude Desktop App — Elastic and Morphisec disclosed details of RevStealer (aka REF2859), a Windows information stealer that comes with an embedded sandbox scoring system and Polygon blockchain-based dead drop for resilience, a technique also called EtherHiding. "Beyond credential theft, REVSTEALER targets gaming platforms for additional monetization; the developer clearly understands that victim accounts on these platforms hold real monetary value in resale markets," Elastic said. The malware is distributed via social engineering attacks, using YouTube videos claiming to advertise hacks for the Albion Online game or rogue GitHub repositories for Anthropic's Claude Opus 5 Free Desktop project. Once installed, the stealer can receive additional executable content through C2 tasks, including additional executable content through (for wallet-file and browser-extension theft, phishing overlays, password-aware input capture, and payload delivery), WinUpdate (for cryptocurrency-address replacement and mnemonic-shaped clipboard theft), SoftManager (for reverse SOCKS5 proxy and backconnect access over an encrypted WebSocket protocol), and LockAppHost (for XMRig deployment, competitor suspension, and persistence). OpenAI Agents Keep Going Rogue — OpenAI is once again in hot water after a swarm of agents self-identifying as from the AI startup hijacked a German website as early as May and used it as a bulletin board for other AI agents. The agent swarm is said to have taken over the obscure German-language wiki in May and June to make around 18,000 posts, relying on it to coordinate on evaluations and swap methods to evade OpenAI’s own controls. The revelations come days after OpenAI published its own detailed account of July's Hugging Face breach in which another swarm of OpenAI agents worked together to escape their sandbox during a cybersecurity evaluation and break into Hugging Face's servers. A subsequent cluster used similar techniques to break into OpenAI's own infrastructure. In response to the wiki incident, OpenAI said it is working on a framework for reporting misalignment incidents during training, evaluation, and deployment. ️🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-78174, CVE-2026-19313, CVE-2026-19318, CVE-2026-19315, CVE-2026-57910, CVE-2026-57909, CVE-2026-13086 (WatchGuard), CVE-2026-80047 (Hugging Face Transformers), CVE-2026-9585, CVE-2026-9586, CVE-2026-9587, CVE-2026-9588 (Sangoma Switchvox SMB), CVE-2026-6881 (Ellucian Advance Web and Legacy Advance), CVE-2026-13381, CVE-2026-13380 (VSee Clinic), CVE-2026-63219, CVE-2026-58400 (GeoNetwork), CVE-2026-9637, CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625, CVE-2026-19471, CVE-2026-19472, CVE-2026-12663, CVE-2026-9633, CVE-2026-9634, CVE-2026-16675, CVE-2025-12768, CVE-2026-84235 (Rockwell Automation), CVE-2026-84115 (Cleo Harmony), CVE-2026-84117, CVE-2026-84118, CVE-2026-84119, CVE-2026-84120, CVE-2026-84121, CVE-2026-84122, CVE-2026-84123, CVE-2026-84124, CVE-2026-84125, CVE-2026-84126 (Mozilla Firefox), CVE-2026-84353, CVE-2026-84352, CVE-2026-85046 (Google Chrome), CVE-2026-19949 (All-in-One WP Migration and Backup), CVE-2026-20277, CVE-2026-20278, CVE-2026-20280, CVE-2026-20279, CVE-2026-20276, CVE-2026-20275, CVE-2026-20274, CVE-2026-20212 (Cisco), CVE-2026-15630 (Casdoor), CVE-2026-73749 (Hewlett Packard Enterprise ArubaOS-CX), CVE-2026-67394 (Plesk), CVE-2026-38577 (Tenda), CVE-2026-6471 aka PostGREShell (PostgreSQL), CVE-2026-42038 (Axios), CVE-2026-64532, CVE-2026-64533 (Linux Kernel), CVE-2026-58048 (cPanel and WHM), CVE-2026-14540 (Google mcp-toolbox), CVE-2026-84645, CVE-2026-84647, CVE-2026-84648, CVE-2026-84649, CVE-2026-84650, CVE-2026-84652, CVE-2026-84665, CVE-2026-84667, CVE-2026-84668, CVE-2026-84669, CVE-2026-84670, CVE-2026-84671, CVE-2026-84672, CVE-2026-84673 (Jenkins), GHSA-x7v6-xfx3-52j6, GHSA-r7jx-j9h7-j4xj, GHSA-9jcm-x588-gh26, GHSA-6mpx-c8rj-whj5, GHSA-q65v-4w7q-hx3r (FreeRDP), CVE-2026-59346, CVE-2026-59347 (Broadcom VMware Workstation and Fusion), CVE-2026-67276, CVE-2026-67277, CVE-2026-67278, CVE-2026-67279, CVE-2026-67281, CVE-2026-86060 (MikroTik RouterOS), CVE-2026-13181, CVE-2026-13182, CVE-2026-13183, CVE-2026-13184, CVE-2026-13185, CVE-2026-13186, CVE-2026-13190 (Telerik UI for ASP.NET AJAX), CVE-2026-86218, CVE-2026-86206, and CVE-2026-86207 (N-able N-central). 🎥 Cybersecurity Webinars A New Vulnerability Drops. Learn How to Find Out ”If You’re Exposed” Faster → Your security tools have the data. Getting an answer shouldn’t take days. See how Tines brings software, cloud, application, and vulnerability data into one dashboard—and learn how to give your team a faster, clearer view of what’s at risk. Find Which Vulnerabilities Attackers Can Actually Exploit—in Hours, Not Weeks → A vulnerability alert doesn’t tell you whether an attacker can break in. Learn how to test exploitability with real-world attack simulations, identify the gaps that matter, and focus remediation on proven risks—not just severity scores. 📰 Around the Cyber World New Knight Office Microsoft 365 AitM Phishing Kit — A new adversary-in-the-middle (AiTM) phishing toolkit called Knight Office has been spotted in the wild using Docusign-themed lures to direct victims to fake landing pages for AitM token theft and device code phishing attacks, joining the likes of EvilTokens and Kali365. The email "led the victim through a number of redirects (including a redirect via the Monday work management platform and a compromised Joomla website)," Huntress said. "The victim landed on a phishing page, where their valid session tokens were captured and fed to the Knight Office console. Session tokens allow attackers to access victim accounts as if they were logged in, without needing an actual password or a way to bypass multi-factor authentication (MFA)." At least nine total phishing attacks on identities have been linked to this kit over the past two weeks. The Blind Spot in SNMPv3 — SNMPv3 — the protocol widely regarded as the secure standard for managing routers, switches, and firewalls — leaks pre-authentication signals that can allow an unauthenticated remote actor to identify a device’s vendor, confirm valid usernames, and narrow its likely encryption settings before testing a single credential. Validated across approximately 470,000 internet-exposed endpoints, the findings show how these standards-compliant behaviors can collapse a multi-dimensional brute-force problem into a focused password-guessing exercise. "SNMPv3 was the industry's answer to insecure network management, and upgrading to it — as the CISA advisory urges — is necessary," said Kobi Ben-Naim, Co-Founder and CEO of Malanta. "But that answer is incomplete. The protocol does exactly what it was designed to do, and that design hands attackers a roadmap: even properly upgraded deployments, when exposed, leak enough through pre-authentication responses to help an attacker narrow their way in before a single credential is tested. The threat doesn't end with the upgrade." U.S. Announces Reward for Senior Iranian Official — A $10 million reward has been posted by the U.S. State Department for information on the whereabouts of senior Iranian official Amir Yaryab. Yaryab allegedly leads the Islamic Revolutionary Guard Corps' (IRGC) Cyber-Electronic Command (CEC). "Yaryab also oversees and controls operations conducted by IRGC-CEC-affiliated groups such as CyberAv3ngers, Dadeh Afzar Arman (DAA), and Mehrsam Andisheh Saz Nik (MASN). These malicious cyber groups have used malware to target civilian infrastructure worldwide," the State Department said. Attack on Coder — Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code to harvest environment variables, API keys, CI/CD credentials, configuration secrets, terminal history, OIDC tokens, SSH keys, external authentication tokens, and Coder database passwords. The data was then exfiltrated to the lookalike domain "coder-infra[.]com." "An unidentified malicious actor gained access to Coder’s Cloudflare infrastructure and added unauthorized IP addresses to the pool used for Coder’s module registry," Coder said. "These unauthorized IP addresses hosted a version of Coder's registry that contained artifacts which included malicious code." Users are advised to look for connections to the malicious domains before applying the latest patches (versions 2.37.0, 2.36.4, 2.35.7, and 2.34.9) U.S.-U.K. Team Up to Shut Down Scam Centers — The U.S. and the U.K. signed a Memorandum of Understanding (MoU) to work together on an initiative to shut down scam centers stealing billions of dollars through investment and romance fraud schemes. "Under the terms of the MOU, each will conduct parallel investigations into common targets, share information on targeting of organized crime syndicates, discuss which jurisdictions to bring specific cases of common interest, and generally prioritize cases on this threat to achieve mutual results," the U.S. Justice Department said. Tampered Exodus Installer Delivers Modular RAT — Victims are being tricked into running a fake PDF document or a software update that leads to the execution of an MSI installer that declares itself a "Background Service" by Apple. "The 'Background Service' installs a genuine Exodus 24.33.4 cryptocurrency wallet, missing one key function: any way for the user to interact with it," Huntress said. "Only 3 of its 1,973 files differ from the real thing. One of those three files stops the wallet from ever drawing a window. Another turns a legitimate Exodus source file into a PE loader that decrypts a 10 MB payload and maps it into memory by hand, where it never touches disk. That payload is the RAT: a hidden VNC and SOCKS proxy that enable remote access and browser credential theft. While the RAT stealthily beacons to Azure Table Storage rather than a domain of its own, it returns every hour through a scheduled task, leaving behind detectable artifacts." QR Phishing With No Image — In a new phishing attack detailed by Kaspersky, threat actors are building a QR code out of text characters and markup directly in the email body as opposed to rendering an image. "There is no attachment to open, no embedded picture to decode, and nothing for an image-based or optical-character-recognition (OCR) scanner to key off," PhishU said. "Because it is markup and not a remote image, an inbox with images turned off still paints it. The message shows a perfectly scannable QR to the human reading it, image-blocking and all." Apple Hit With $2.7 Billion Lawsuit Over App Tracking Rules — Apple is facing a £2 billion ($2.7 billion) lawsuit in the U.K. accusing it of imposing stricter App Tracking Transparency rules on third-party developers than on its own advertising services, thereby giving its ecosystem a competitive advantage, according to Reuters. Apple's App Tracking Transparency feature has been the subject of extensive investigations across Europe. Last month, Apple agreed to make changes to the feature across almost all European Union countries following a probe in Germany. Attackers Routinely Target Edge Devices — A joint analysis from SentinelOne and Tenable found that both nation-state and criminal threat actors are focusing on vendors and susceptible points in the attack surface more than specific CVEs. "Both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure," the companies said. "The exposure picture is flatter than the headlines suggest: Fortinet, the vendor most associated with edge-device attacks in the press, sits mid-pack on container-grain exposure (25%) — well behind F5 (54%) and in a tight 10-point band with Check Point, Ivanti, and Citrix. 54% of customer environments running F5 products have at least one exposed, actively-exploited CVE; Citrix customers show the slowest remediation patterns at 461 days median time to patch." The disclosure comes as current attacker timelines are compressing and moving faster than standard patch cycles can address, driven by frontier AI models that narrow the window between vulnerability discovery and exploitation. The Threat of Indirect Prompt Injection — New research from Forcepoint revealed that an email summarizer running an unguarded LLM pipeline can be manipulated through indirect prompt injection (i.e., hidden instructions in an email) to silently hijack summarizer output and generate false and potentially dangerous summaries without signaling tampering to the recipient. It's the latest example of how attackers can use indirect prompt injections to undermine AI systems and get them to behave in unintended ways when processing external content. It's also a reminder of AI's fundamental limitations. Large language models (LLMs) cannot distinguish between authentic user instructions entered directly into a prompt and content they find on untrusted third-party sources, leading to prompt injections. "A regular Outlook email composer does strip styling that hides elements on copy/paste and does not provide any way to hide text other than white text on white background," Forcepoint said. "The hidden styling was not stripped when sent programmatically, or when the message is received and displayed. Hidden HTML tags like these have been commonly used by attackers to circumvent careful reading by victims." Conclusion Trusted sources and safer settings still have limits. This week’s attacks show why it matters to know exactly what each protection covers—and what it leaves exposed. Keep patching, but keep the logs needed to investigate, too. “Fully patched” tells you which fixes are installed. It doesn’t prove nobody got in.
thehackernews.comSep 7, 2026extracted
Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication
Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication Attackers are exploiting a chain of RouterOS vulnerabilities to hijack MikroTik devices with SSH open to the internet, CERT Polska found. CERT Polska, Poland’s national CSIRT team, have discovered six vulnerabilities in RouterOS and coordinated their disclosure with MikroTik. Among the six, two combined let an attacker take full control of a device without authentication, provided the device has SSH accessible from the internet. They named this exploit chain MikroTrick. “In recent days we have been observing attacks against RouterOS devices accessible from the internet. We have obtained confirmation that the attackers are exploiting this combination of vulnerabilities to take full control of devices whose SSH service is accessible from public networks,” the CERT Polska team wrote. “It has also been confirmed that the released patches prevent the observed attacks. We recommend applying the update immediately,” they added. The vulnerabilities were discovered using the GPT-5.5-cyber and GPT-5.6-sol models, through the team’s access to OpenAI’s Government and Trust Agency Collaboration program. “At least 122,500 MikroTik devices with SSH accessible found per 24 hour scan window on 2026-09-05 (no vulnerability check),” the Shadowserver Foundation posted on Mastodon. Traces of compromise One of the flaws, CVE-2026-67276 (CVSS 9.2), is an SSH authentication bypass caused by RouterOS comparing only the public modulus of a user’s RSA key instead of the entire key, letting an attacker who knew a username and its modulus craft a different key and log in without the private key, gaining that account’s privileges. CVE-2026-86060 (also CVSS 9.2) is a privilege escalation flaw in how RouterOS handled SSH usernames beginning with a disallowed character, letting an attacker craft a username that returned a session with full administrative privileges. A third flaw, CVE-2026-67277 (CVSS 8.8), is in the bandwidth-test service, which let unauthenticated connections reach a state normally reserved for logged-in users. Combined with a leak of uninitialized packet-buffer data and an integer underflow in size validation, this could expose kernel memory or crash the device into a restart. Three additional, lower-severity vulnerabilities affect the SSH client, X.509 certificate handling, and the WebFig interface. The researchers listed the following log entries as indicators of the observed attacks: login failure for user -2 from via ssh user added by ssh:-2@ A highly privileged user named “ops” showing up unexplained is another indicator. The team traced the confirmed successful attacks, including creation of that “ops” account, to the IP address 82.192.72.4, active since at least September 2, and it flagged a second address, 103.102.31.18, used in attempts to exploit the same chain. Patches and detection MikroTik released fixes in RouterOS versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, listed in its security bulletin. “This is an important security update. Most configurations are not at risk, but upgrading is highly recommended. To give time to update your systems, we are not currently publishing detailed information,” MikroTik noted. “For regular home device users the issue does not pose an immediate risk, but we still suggest all users to upgrade.” The patched versions include a mechanism that scans the configuration at startup for known signs of unauthorized changes, disables recognized suspicious entries, writes a message to the log, and sets a “Flagged” marker. “Even if your device is not in Flagged state, after upgrading your RouterOS, inspect your device configuration for any unknown scripts, users or other config you do not recognise,” MikroTik added. Recommendations CERT Polska recommends updating RouterOS immediately to 7.25beta3, 7.24.2, 7.23.4, or 6.49.21, then checking logs for the compromise message and the flagged marker value in the output of the /system/device-mode/print command, and reviewing the configuration for unknown users, scripts, and other unrecognized changes. If the patch cannot be installed immediately, it recommends disabling exposed services, including SSH, WWW/WWW-SSL, and the bandwidth-test server, or restricting them to trusted management networks, and avoiding TLS connections or the built-in SSH client from an unpatched device over untrusted networks. “These are only temporary measures that reduce the attack surface. They do not replace installing the patched RouterOS version.” Researchers published this information on an accelerated schedule because the patched packages are already public, and comparative analysis of them has allowed the community to reconstruct some of the fixed bugs. “We limit the description to the information administrators need and do not publish exploit code or details that would make automating attacks easier,” they concluded.
helpnetsecurity.comSep 7, 2026extracted
Hackers exploit new MikroTik RouterOS flaws to hijack routers
Hackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet. One of the security issues, tracked as CVE-2026-67276, is an SSH authentication bypass flaw in MikroTik RouterOS caused by incomplete validation of RSA public keys. An attacker who knows a username and the public modulus of that user’s key can exploit it by crafting a different key and logging in without the legitimate private key. The second security issue is identified as CVE-2026-86060. It is an SSH privilege escalation flaw in MikroTik RouterOS due to improper handling of specially crafted usernames. Hackers can leverage it using a specially crafted username to manipulate the SSH session so that the attacker obtains full administrative privileges. Both vulnerabilities were discovered by Poland's CERT agency with the help of GPT-5.5-cyber and GPT-5.6-sol and received a critical severity rating. The Polish agency dubbed the exploit chain “MikroTrick,” and warned that it is now actively exploited in the wild. “In recent days we have been observing attacks against RouterOS devices accessible from the internet,” Poland's CERT warns. “We have obtained confirmation that the attackers are exploiting this combination of vulnerabilities to take full control of devices whose SSH service is accessible from public networks.” The Polish CERT also highlighted a third flaw, CVE-2026-67277, which affects the RouterOS bandwidth-test service and allows unauthenticated attackers to leak kernel memory or to remotely crash/restart the router. MikroTik fixed the vulnerabilities in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, released on September 3, and Poland's CERT validated the fixes. In its advisory, the vendor notes that not all configurations are affected, but did not disclose any details to give users time to apply the security updates. The updates add a compromise-detection mechanism to the routers that looks for known signs of unauthorized configuration changes at startup, disables malicious entries, and logs a critical warning. However, the CERT notes that the absence of a marker indicating compromise should not be taken as a guarantee that a router has not been compromised. The CERT shared the following indicators of compromise (IoCs): Log entries: ‘login failure for user -2 from via ssh’ and ‘user added by ssh:-2@ ’ Presence of a highly privileged ops account 82.192.72.4 — linked to confirmed successful attacks 103.102.31.18 — observed attempting to exploit MikroTrick If compromise is suspected, the Polish agency recommends isolating the router, preserving logs and configuration, then factory-resetting the device and rebuilding it from a trusted configuration while rotating passwords, keys, and other secrets. For those unable to apply the updates immediately, one recommendation is to restrict or disable externally accessible SSH, WWW/WWW-SSL, and bandwidth-test services, and avoid the built-in SSH clients and outbound TLS connections over untrusted networks. As of September 5, there were 122,500 MikroTik devices with an exposed SSH interface, according to data provided by The ShadowServer Foundation. The exact number of devices vulnerable the MikroTik exploit was not determined, though. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comSep 7, 2026extracted