MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication.

The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Tile’s security is so bad it’s a feature for stalkers

Tile’s security is so bad it’s a feature for stalkers Source: Hacker News

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel

Attack Update: Top 5 Attack-IPs auf doode.info – 30.06.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 β€” 225 requests (recent log) 159.195.82.218 β€” 144 requests (recent log) 5.255.97.193 β€” 88 requests (recent