Act
active
Attackers Hijack MikroTik Routers via Unauthenticated SSH
- Engineer — Act: Active exploitation of internet-exposed MikroTik SSH granting full admin access is confirmed by CERT Polska; immediately audit all MikroTik devices for internet-reachable SSH, restrict SSH to management-only networks, and review recent device configurations for unauthorized changes since September 2.
- SOC/IR — Act: Edge device full-takeover with confirmed active exploitation since at least September 2 is an assume-breach signal; sweep MikroTik routers for unauthorized admin sessions and configuration changes, and check for anomalous outbound traffic from these devices as a lateral-movement indicator.
- Leader — Plan: MikroTik is common in SMB and branch-office environments; direct the security team to inventory internet-facing MikroTik SSH exposure and confirm whether any devices were reachable since September 2 — not yet a systemic board-level event but escalate if exposure is confirmed.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.