Find notable cyber news and cases, enriched with sources, timelines, and signals.

MikroTik RouterOS SSH exploitation wave

Exploitation Wave
First reported
Last updated
Happening score
H score 7
1 unique sources, 1 articles

Summary

Hide ▲

Internet-exposed MikroTik routers are under active abuse through SSH to produce full administrative control without authentication. Successful attacks were observed from at least September 2, and CERT Polska issued a warning on September 5. MikroTik’s fixed RouterOS releases and the recommended immediate update show an active exposure risk for publicly reachable management services.

Related Happenings

CERT Polska private APN hardening recommendations

Advisory/Mitigation
H score29 First: 11.08.2026 09:55 Last: 11.08.2026 09:55 Sources 1

About this happening: CERT Polska issued mitigation guidance for private APNs used to reach OT equipment after a real intrusion path into a Polish CHP plant. The recommendations focus on clie...

Forest Blizzard DNS hijacking token-theft campaign against older routers

Campaign
H score35 First: 07.04.2026 20:02 Last: 07.04.2026 20:02 Sources 1

About this happening: Russia-backed Forest Blizzard is running a DNS hijacking campaign against older routers to steal Microsoft Office authentication tokens, putting accounts at risk acros...

APT28 FrostArmada DNS hijacking and AitM credential theft campaign

Campaign
H score45 First: 07.04.2026 18:51 Last: 07.04.2026 18:51 Sources 1

About this happening: A multinational disruption effort has taken down FrostArmada, an APT28 campaign that hijacked router DNS settings to steal Microsoft account credentials and OAuth toke...

Zyxel security patch release for CVE-2025-13942

Security Patch Release
H score27 First: 25.02.2026 14:53 Last: 25.02.2026 14:53 Sources 1

About this happening: Zyxel released security updates for over a dozen router models, closing CVE-2025-13942 and two related command-injection flaws that could let attackers run OS comm...

Poland's energy sector hit by network compromise

Incident
H score30 First: 17.02.2026 23:31 Last: 17.02.2026 23:31 Sources 1

About this happening: A destructive cyberattack on Poland's energy sector unfolded on December 29-30, 2025, hitting renewable energy farms and a combined heat and power plant. Polis...

Timeline

  1. 06.09.2026 12:32 2 articles · 2h ago

    Exposed MikroTik routers are exploited through SSH

    Exploitation Observed

    Attackers exploit internet-exposed Secure Shell (SSH) remote-access on MikroTik routers to gain full administrative control without authentication, and CERT Polska says successful attacks were already occurring by September 2.

    Show sources
  2. 05.09.2026 03:00 1 articles · 1d ago

    CERT Polska warns of unauthenticated MikroTik SSH takeovers

    Initial Disclosure

    CERT Polska warns that attackers are abusing internet-exposed SSH on MikroTik routers to obtain full administrative control without authentication and maps affected RouterOS branches to fixed releases, urging immediate installation and a review for unauthorized configuration changes.

    Show sources