MikroTik RouterOS SSH exploitation wave
Exploitation Wave
Summary
Hide ▲
Show ▼
Internet-exposed MikroTik routers are under active abuse through SSH to produce full administrative control without authentication. Successful attacks were observed from at least September 2, and CERT Polska issued a warning on September 5. MikroTik’s fixed RouterOS releases and the recommended immediate update show an active exposure risk for publicly reachable management services.
Related Happenings
CERT Polska private APN hardening recommendations
Advisory/Mitigation
H score29
First: 11.08.2026 09:55
Last: 11.08.2026 09:55
Sources 1
About this happening:
CERT Polska issued mitigation guidance for private APNs used to reach OT equipment after a real intrusion path into a Polish CHP plant. The recommendations focus on clie...
CERT Polska private APN hardening recommendations
Advisory/MitigationAbout this happening: CERT Polska issued mitigation guidance for private APNs used to reach OT equipment after a real intrusion path into a Polish CHP plant. The recommendations focus on clie...
Forest Blizzard DNS hijacking token-theft campaign against older routers
Campaign
H score35
First: 07.04.2026 20:02
Last: 07.04.2026 20:02
Sources 1
About this happening:
Russia-backed Forest Blizzard is running a DNS hijacking campaign against older routers to steal Microsoft Office authentication tokens, putting accounts at risk acros...
Forest Blizzard DNS hijacking token-theft campaign against older routers
CampaignAbout this happening: Russia-backed Forest Blizzard is running a DNS hijacking campaign against older routers to steal Microsoft Office authentication tokens, putting accounts at risk acros...
APT28 FrostArmada DNS hijacking and AitM credential theft campaign
Campaign
H score45
First: 07.04.2026 18:51
Last: 07.04.2026 18:51
Sources 1
About this happening:
A multinational disruption effort has taken down FrostArmada, an APT28 campaign that hijacked router DNS settings to steal Microsoft account credentials and OAuth toke...
APT28 FrostArmada DNS hijacking and AitM credential theft campaign
CampaignAbout this happening: A multinational disruption effort has taken down FrostArmada, an APT28 campaign that hijacked router DNS settings to steal Microsoft account credentials and OAuth toke...
Zyxel security patch release for CVE-2025-13942
Security Patch Release
H score27
First: 25.02.2026 14:53
Last: 25.02.2026 14:53
Sources 1
About this happening:
Zyxel released security updates for over a dozen router models, closing CVE-2025-13942 and two related command-injection flaws that could let attackers run OS comm...
Zyxel security patch release for CVE-2025-13942
Security Patch ReleaseAbout this happening: Zyxel released security updates for over a dozen router models, closing CVE-2025-13942 and two related command-injection flaws that could let attackers run OS comm...
Poland's energy sector hit by network compromise
Incident
H score30
First: 17.02.2026 23:31
Last: 17.02.2026 23:31
Sources 1
About this happening:
A destructive cyberattack on Poland's energy sector unfolded on December 29-30, 2025, hitting renewable energy farms and a combined heat and power plant. Polis...
Poland's energy sector hit by network compromise
IncidentAbout this happening: A destructive cyberattack on Poland's energy sector unfolded on December 29-30, 2025, hitting renewable energy farms and a combined heat and power plant. Polis...
Timeline
-
06.09.2026 12:32 2 articles · 2h ago
Exposed MikroTik routers are exploited through SSH
Exploitation ObservedAttackers exploit internet-exposed Secure Shell (SSH) remote-access on MikroTik routers to gain full administrative control without authentication, and CERT Polska says successful attacks were already occurring by September 2.
Show sources
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication — thehackernews.com — 06.09.2026 12:32
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication — thehackernews.com — 06.09.2026 12:32
-
05.09.2026 03:00 1 articles · 1d ago
CERT Polska warns of unauthenticated MikroTik SSH takeovers
Initial DisclosureCERT Polska warns that attackers are abusing internet-exposed SSH on MikroTik routers to obtain full administrative control without authentication and maps affected RouterOS branches to fixed releases, urging immediate installation and a review for unauthorized configuration changes.
Show sources
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication — thehackernews.com — 06.09.2026 12:32