Cybersecurity · September 7, 2026
CERT Polska has warned that attackers are seizing control of MikroTik routers whose SSH management port is left open to the public internet, letting them log in as administrators with no valid credentials at all. The warning, issued September 5, says the intrusions have been happening since at least September 2, though the total number of compromised devices is not yet known. The advisory urges network operators to firewall off remote SSH access rather than exposing it directly.
// source: thehackernews.com ↗