Hackers are actively exploiting a chain of two newly disclosed vulnerabilities in MikroTik RouterOS to seize control of routers with exposed SSH services. The attacks target internet-facing devices and pose immediate risk to affected networks.
■ Attack Details
Security researchers have documented active exploitation of two linked vulnerabilities in MikroTik RouterOS. The flaws enable attackers to gain unauthorized access to routers when Secure Shell (SSH) services are accessible from the internet.
The vulnerability chain works by chaining multiple weaknesses together, allowing attackers to escalate privileges and achieve full device control. Once compromised, routers become entry points for broader network intrusions.
■ Affected Systems
MikroTik RouterOS devices with SSH exposed to the internet are at highest risk. Organizations running public-facing routers without proper access restrictions are primary targets.
■ Mitigation Steps
MikroTik has released patches addressing the disclosed flaws. Organizations should:
- Update RouterOS to the latest patched version immediately
- Restrict SSH access to trusted IP addresses only
- Disable SSH if remote management is not required
- Use VPN or bastion hosts for administrative access
- Monitor router logs for suspicious connection attempts
■ Industry Impact
MikroTik routers are widely deployed in small business networks, ISPs, and service provider environments. The active exploitation of these vulnerabilities increases urgency for network administrators to apply fixes.
Previous MikroTik vulnerabilities have been weaponized by threat actors within days of disclosure. Security teams should prioritize patching as an immediate action item.
Security researchers discovered that LG smart TVs continue recording audio and scanning local networks even when the display is powered down. The findings raise concerns about user privacy and device security.
ConnectWise has disclosed a new vulnerability in ScreenConnect remote access software without an immediate patch available. The company is offering temporary mitigation measures while preparing a fix for later this week.
N-able has released an emergency hotfix for a maximum-severity remote code execution vulnerability in its N-central RMM platform. The flaw is being actively exploited in ongoing attacks.
QBittorrent, the popular open-source torrent client, has been found capable of breaking out of sandbox environments to execute unauthorized operations. Security researchers identified the vulnerability, raising concerns about the application's access to system resources.