Attackers Exploit MikroTik Routers via Internet-Exposed SSH, CERT Polska Warns
Attackers are actively exploiting MikroTik routers with internet-exposed Secure Shell (SSH) remote-access services to gain full administrative control without authentication, according to a warning issued by CERT Polska on September 5. The attacks have been observed since at least September 2. While CERT Polska's warning and a subsequent review by The Hacker News on September 6 did not specify the number of victims or the attackers' identities, MikroTik has released security updates to address the vulnerabilities. CERT Polska recommends immediate installation of these updates and a thorough check for unauthorized configuration changes. The vulnerabilities, collectively termed 'MikroTrick' by CERT, allow attackers to bypass authentication and gain administrative access, posing a significant threat to affected devices.