Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Attackers are exploiting exposed MikroTik RouterOS SSH services to gain full administrative control without authentication, with CERT Polska warning that successful attacks have been observed since at least September 2. CERT and MikroTik urge immediate patching, service restrictions, and careful post-update checks for suspicious changes, while the reported two-flaw chain dubbed MikroTrick remains under investigation. #CERTPolska #MikroTik #RouterOS #MikroTrick

Keypoints

  • Attackers are abusing exposed MikroTik RouterOS SSH access to take full admin control.
  • CERT Polska says successful attacks have been happening since at least September 2.
  • MikroTik has released fixed RouterOS versions, and immediate updating is recommended.
  • Temporary mitigations include disabling exposed services and restricting management access to trusted networks.
  • CERT advises checking logs, users, scripts, and device status for signs of compromise.

Read More: https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html