MikroTik Routers Hijacked via Internet-Exposed SSH Without Authentication
CERT Polska warns of active exploitation targeting routers with SSH reachable from the internet

Key Takeaways
- MikroTik routers with internet-exposed SSH are being targeted for unauthenticated administrative compromise.
- Exploitation has been observed since at least September 2, 2026, following a CERT Polska warning on September 5.
- No specific vulnerability or CVE is reported; the issue stems from misconfigured or default SSH access on internet-facing devices.
Related Security News

CrowdSec GitHub Compromise via Former Employee OAuth Token
CrowdSec confirmed that threat actors gained unauthorized access to 170 private repositories on GitHub by leveraging an OAuth token stolen from a former employee's personal computer. The attack vector involved a supply chain compromise of the TanStack npm package, which was used to facilitate access to the GitHub resources. The incident was first reported by Dark Reading on September 22, 2026. CrowdSec has indicated that the compromised OAuth tokens have been revoked and additional access controls may have been implemented, though specific technical details of the supply chain mechanism remain limited in the public report.




