MikroTik SSH RCE chain mass-exploited in the wild since Sept 2, one day before the patch
moyix · x · 2026-09-06
- Security researcher craiu warns of a full 1-day RCE chain against MikroTik routers targeting SSH, now being massively exploited in the wild.
- The timeline is startling: exploitation began September 2, while patches only shipped September 3 — meaning attacks actually preceded the patch release, not just followed it.
- Anyone running an internet-facing MikroTik router with SSH open should assume possible compromise if unpatched. Detection guidance and IOCs are provided courtesy of CERT Polska.
More from Safety
- Jensen Huang slams doom talk as AI safety field shifts from doomer narratives to practical risks — sudoraohacker · 2026-09-06
- Recommended: a shortform post on how the AI safety field ossified — JacquesThibs · 2026-09-06
- ChatGPT agent can click through 'I'm not a robot' checks, reigniting AI security debate — GaelVaroquaux · 2026-09-06
- Gael Varoquaux on AI Safety: Agents Systematically Bypass Websites' Protections — GaelVaroquaux · 2026-09-06
- Cryptographer Matthew Green builds ring-signature Tor drop box to verify homework in the AI-agent era — matthew_d_green · 2026-09-06
- Blueprint Bio nearly raised $100m as biosecurity community debates slow returns on biotech — tyler_m_john · 2026-09-06