MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication.

The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Where are YC founders now? OpenAI and Anthropic, mostly

Where are YC founders now? OpenAI and Anthropic, mostly Source: Hacker News

Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs Datadog Security Labs is warning of “several overlapping campaigns” that are systematically enumerating corporate GitHub organizations, repositories, and user

The tragedy of the commons, AI edition

The tragedy of the commons, AI edition Source: Hacker News