CERT Polska issued a warning on September 5 regarding active exploitation of MikroTik routers. Attackers are targeting routers with Secure Shell (SSH) remote-access services exposed to the internet, enabling them to gain full administrative control without requiring authentication. Successful attacks have been observed since at least September 2.
MikroTik has released security updates for its RouterOS, listing fixed versions that prevent the observed attacks. CERT Polska strongly recommends immediate installation of these updates. Following the update, users should check their router configurations for any unauthorized changes that may have occurred.
Until updates can be installed, CERT Polska advises turning off exposed services like SSH, WWW/WWW-SSL, and bandwidth-test, or restricting access to trusted management networks. They also recommend against initiating TLS connections or using RouterOS's built-in SSH clients from unpatched devices. If compromise is suspected, CERT recommends isolating the router, preserving logs and configuration, restoring factory settings, and rebuilding with a verified configuration.
MikroTik's RouterOS can flag devices when suspicious configurations are detected during startup, disabling affected entries and restricting functions. After updating, users should check logs and run '/system/device-mode/print' to inspect the device status. Signs of compromise include unknown users, scripts, unrecognized changes, unexpected highly privileged operations accounts, and account-creation logs containing 'ssh:-2@'.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Attackers are exploiting MikroTik routers with internet-exposed SSH services to gain full administrative control without authentication, according to CERT Polska. MikroTik has released security updates for RouterOS to address these vulnerabilities, and users are advised to install them immediately.