MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication.

The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

From brain waves to words: a new path to communication without surgery

From brain waves to words: a new path to communication without surgery Source: Hacker News

Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out