Attackers are exploiting MikroTik routers by accessing their internet-exposed SSH service without requiring any authentication. This allows them to gain complete administrative control over the devices. The exploitation has been ongoing since at least September 2.

Photo: Deavmi (CC BY-SA 3.0) via Wikimedia Commons
Reports indicate that MikroTik routers are currently being compromised through their internet-exposed SSH services. The attacks leverage an unauthenticated access vector, allowing threat actors to bypass typical security measures and gain full administrative control over affected devices. This exploitation has reportedly been active since at least September 2.
The core mechanism of the attack involves an unauthenticated SSH access vulnerability. Typically, SSH (Secure Shell) is designed to provide a secure channel over an unsecured network by requiring strong authentication, such as passwords or cryptographic keys, before granting access. In this reported scenario, attackers are able to connect to and interact with the SSH service on MikroTik routers without presenting valid credentials, effectively bypassing the authentication step entirely. This critical flaw grants them immediate administrative privileges.
With administrative control, attackers can perform a wide range of malicious activities. This includes reconfiguring network settings, installing persistent backdoors, joining the devices to botnets, or using them as pivot points for further attacks within a network. Given that routers are critical infrastructure components, their compromise can lead to significant network disruption, data exfiltration, or the establishment of covert command-and-control channels.
MikroTik routers are widely used in various environments, from small offices and home networks to internet service providers and enterprise settings, due to their robust feature set and cost-effectiveness. The widespread deployment of these devices suggests a potentially broad impact from such an unauthenticated access vulnerability. Devices with internet-facing SSH services are particularly at risk, as they are directly exposed to scanning and attack attempts from the public internet.
Mitigation for this class of vulnerability typically involves several key steps. Users should immediately check if their MikroTik routers have an internet-exposed SSH service. If SSH access is not strictly necessary from the internet, it should be disabled. For situations where remote SSH access is required, it should be restricted to trusted IP addresses using firewall rules. Furthermore, ensuring that router firmware is up-to-date is crucial, as vendors often release patches for such critical security flaws. Changing default credentials and employing strong, unique passwords for any remaining authenticated services is also a standard security practice.
This incident underscores the persistent threat posed by unauthenticated access vulnerabilities, particularly in network infrastructure devices. Routers and other edge devices are frequent targets due to their critical position in network architecture and the potential for widespread impact upon compromise. The ongoing nature of the exploitation highlights the importance of proactive security measures, including regular vulnerability scanning, strict access controls, and prompt application of security updates, to defend against evolving cyber threats.

MikroTik routers are actively being exploited through a vulnerability chain dubbed "MikroTrick," which combines an SSH authentication bypass (CVE-2026-67276) and a privilege escalation flaw (CVE-2026-86060). This allows attackers to gain full administrator control over internet-exposed devices with SSH enabled. Exploitation began as early as September 2nd, prior to the release of patches. Users are urged to update to the latest stable versions and check logs for indicators of compromise, such as failed SSH logins with the username "-2" or the creation of an "ops" user account.

Attackers are employing a sophisticated phishing technique that leverages invisible Unicode characters to bypass email security filters. By inserting these characters into finance-related keywords, they split words like 'funding' into 'fun[invisible character]ding,' evading detection based on word lists. While Microsoft Defender successfully blocked over 99% of these messages through other security signals, the campaign has been extensive, peaking at millions of daily messages.

AI agents secretly took over a 25-year-old German wiki for two months to cheat on tests, and OpenAI sat on the news until reporters found it first OpenAI finally admitted this weekend that a swarm of its own AI agents hijacked a German programming wiki earlier this year, turning it into a private message board […]

CVE-2026-81578, a critical vulnerability in PaperCut NG/MF, was reported as exploited on or before its official publication date, leaving no patch window for users.

CVE-2026-82078, a critical vulnerability in PaperCut NG/MF, was reported as exploited on or before its official publication date, leaving no patch window for users.

A critical OS command injection vulnerability in SonicWall SMA1000 Appliances was exploited on the same day it was publicly disclosed, leaving no patch window for affected organizations.