daily cyber × ai intelligence

index

tagged

[CVE-2026-67276]

3 editions · 3 items

September 9, 2026

  • CERT Poland put CVEs and IoCs on the MikroTik takeovers: CVE-2026-67276 (SSH auth bypass) chained with CVE-2026-86060 (SSH session privilege manipulation) has been used since at least 2 September against devices with SSH reachable from the internet, creating an account named ops, from 82.192.72.4 and 103.102.31.18. Shadowserver saw more than 120,000 MikroTik devices with SSH exposed during a 24-hour scan window on 5 September; fixes are in RouterOS 7.25beta3, 7.24.2, 7.23.4 and 6.49.21 (SecurityWeek) (earlier coverage). · Patch Tuesday & Active Exploitation

in One Phone Call, Zero Clicks: A WeChat Worm Crossed iOS and Android

September 7, 2026

  • MikroTik's three same-day RouterOS builds (7.23.4 long-term, 7.24.2 stable, 6.49.21) shipped with a deliberately vague "important security update" banner — and one changelog line present in all three branches, absent from 7.23.3: "ssh - refactor SSH internal processes". Diffing the NPK packages, npratley.net documents three bugs and two chains: a low-exponent RSA signature forgery reaching an overflow in mtget with confirmed controlled code execution, and — matched to an active-exploitation support trace — an SSH username of -2 reaching a legacy file-descriptor login transport, letting a read-only session supply its own policy mask and escalate to the full RouterOS policy set, producing exactly the campaign-shaped ops account defenders have been finding. The author is explicit about the boundary he did not cross: he has not reproduced a stock, credential-free way to make SSH accept literal user -2. The work was AI-driven and took roughly six hours. A MikroTrick PoC is public, tracked as CVE-2026-67276. CERT Polska's warning went out 5 September with attacks dating to at least 2 September and no victim count; CERT-LV described mass attacks (@campuscodi); SANS ISC says assume compromise, because attackers are adding accounts that survive the patch (earlier coverage). · Exploitation & Active Attacks

in The Diff Is the Disclosure: MikroTik's Silent Patch Comes Apart