daily cyber × ai intelligence

index

tagged

[mikrotik]

3 editions · 3 items

September 8, 2026

  • MikroTik hunting guidance is now concrete. CERT Polska points to unexpected highly privileged ops accounts and account-creation log entries containing ssh:-2@ as investigation triggers, plus RouterOS Flagged status via /system/device-mode/print — preserve evidence before clearing Flagged. Fixed builds are 6.49.21, 7.23.4 (use 7.23.5 on long-term, which corrects an IPv6 DHCP regression), and 7.24.2. Attacks date to at least 2 September with patches on the 3rd, which The Hacker News notes does not by itself establish zero-day status (The Hacker News, earlier coverage). · Vulnerabilities & Exploits

in N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited

September 7, 2026

  • MikroTik's three same-day RouterOS builds (7.23.4 long-term, 7.24.2 stable, 6.49.21) shipped with a deliberately vague "important security update" banner — and one changelog line present in all three branches, absent from 7.23.3: "ssh - refactor SSH internal processes". Diffing the NPK packages, npratley.net documents three bugs and two chains: a low-exponent RSA signature forgery reaching an overflow in mtget with confirmed controlled code execution, and — matched to an active-exploitation support trace — an SSH username of -2 reaching a legacy file-descriptor login transport, letting a read-only session supply its own policy mask and escalate to the full RouterOS policy set, producing exactly the campaign-shaped ops account defenders have been finding. The author is explicit about the boundary he did not cross: he has not reproduced a stock, credential-free way to make SSH accept literal user -2. The work was AI-driven and took roughly six hours. A MikroTrick PoC is public, tracked as CVE-2026-67276. CERT Polska's warning went out 5 September with attacks dating to at least 2 September and no victim count; CERT-LV described mass attacks (@campuscodi); SANS ISC says assume compromise, because attackers are adding accounts that survive the patch (earlier coverage). · Exploitation & Active Attacks

in The Diff Is the Disclosure: MikroTik's Silent Patch Comes Apart