<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Edge-Device on CuraSec</title><link>https://curasec.metacog.co.kr/tags/edge-device/</link><description>Recent content in Edge-Device on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 06 Sep 2026 14:08:28 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/edge-device/index.xml" rel="self" type="application/rss+xml"/><item><title>Attackers Hijack MikroTik Routers via Unauthenticated SSH</title><link>https://curasec.metacog.co.kr/insights/2026-09-06-attackers-hijack-mikrotik-routers-through-internet-exposed-s/</link><pubDate>Sun, 06 Sep 2026 14:08:28 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-06-attackers-hijack-mikrotik-routers-through-internet-exposed-s/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Active exploitation of internet-exposed MikroTik SSH granting full admin access is confirmed by CERT Polska; immediately audit all MikroTik devices for internet-reachable SSH, restrict SSH to management-only networks, and review recent device configurations for unauthorized changes since September 2.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Edge device full-takeover with confirmed active exploitation since at least September 2 is an assume-breach signal; sweep MikroTik routers for unauthorized admin sessions and configuration changes, and check for anomalous outbound traffic from these devices as a lateral-movement indicator.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> MikroTik is common in SMB and branch-office environments; direct the security team to inventory internet-facing MikroTik SSH exposure and confirm whether any devices were reachable since September 2 — not yet a systemic board-level event but escalate if exposure is confirmed.&lt;/li>
&lt;/ul></description></item></channel></rss>