daily cyber × ai intelligence

index

tagged

[CVE-2026-86060]

2 editions · 2 items

September 9, 2026

  • CERT Poland put CVEs and IoCs on the MikroTik takeovers: CVE-2026-67276 (SSH auth bypass) chained with CVE-2026-86060 (SSH session privilege manipulation) has been used since at least 2 September against devices with SSH reachable from the internet, creating an account named ops, from 82.192.72.4 and 103.102.31.18. Shadowserver saw more than 120,000 MikroTik devices with SSH exposed during a 24-hour scan window on 5 September; fixes are in RouterOS 7.25beta3, 7.24.2, 7.23.4 and 6.49.21 (SecurityWeek) (earlier coverage). · Patch Tuesday & Active Exploitation

in One Phone Call, Zero Clicks: A WeChat Worm Crossed iOS and Android