<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication]]></title><description><![CDATA[<p dir="auto">Attackers are actively compromising MikroTik routers by targeting the devices' Secure Shell (SSH) remote-access service when it is exposed to the internet. According to an attack warning published by CERT Polska on September 5, the threat actors are able to gain full administrative control over the affected routers <em>without</em> requiring any authentication.</p>
<p dir="auto">Successful exploitation attempts have been observed dating back to at least September 2. CERT Polska has not disclosed the total number of victims affected by this campaign, nor does the advisory currently specify a unique identifier for the underlying flaw. Instead, the warning highlights the danger of leaving the SSH interface reachable from the public internet, as this configuration effectively allows unauthorized parties to bypass login credentials entirely.</p>
<ul>
<li>Affected component: MikroTik RouterOS SSH service</li>
<li>Attack vector: Internet-exposed SSH interface</li>
<li>Impact: Full administrative control of the router</li>
</ul>
<p dir="auto">Organizations using MikroTik hardware should immediately restrict remote access to the SSH service, either by disabling it entirely or by limiting exposure via firewall rules to trusted IP addresses only. Administrators are also advised to audit device logs for any unauthorized configuration changes or unknown user accounts that may indicate prior compromise.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Is your organization currently running any MikroTik routers with SSH exposed to the internet, and if so, what immediate steps are you taking to lock down access?</p>
]]></description><link>https://xploitlk.com/topic/236/attackers-hijack-mikrotik-routers-through-internet-exposed-ssh-without-authentication</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 06:25:21 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/236.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 06 Sep 2026 10:30:21 GMT</pubDate><ttl>60</ttl></channel></rss>