Hackers exploit new MikroTik RouterOS flaws to hijack routers
Summary
Hackers are actively exploiting a combination of two recently disclosed vulnerabilities in MikroTik RouterOS to gain unauthorized control of routers. The attackers target devices with SSH services exposed to the internet, indicating a critical security risk for affected users.
IFF Assessment
The exploitation of vulnerabilities by hackers to gain control of network devices represents a direct threat to the security and integrity of systems, making it bad news for defenders.
Severity
This score is estimated due to the exploitation of two chained vulnerabilities allowing remote code execution and full control over network devices with internet-exposed SSH, suggesting a high attack vector and impact.
Defender Context
This highlights the critical need for defenders to promptly patch MikroTik routers, especially those with exposed SSH services. Attackers are actively leveraging chained vulnerabilities for device hijacking, emphasizing the importance of network segmentation and access control.