MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication.

The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers A crafted SVG submitted to Bing’s image search ran commands as NT AUTHORITY\SYSTEM on Microsoft’s production image-processing

Linux on ESP32

Linux on ESP32 Source: Hacker News

Snails’ Teeth Beats Spider Silk as Nature’s Strongest Material (2015)

Snails’ Teeth Beats Spider Silk as Nature’s Strongest Material (2015) Source: Hacker News