Skip to content
archiveexploit · 06 Sep 2026 · 09:32 UTC

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

SHODANShodan: ~196,500 MikroTik exposed worldwide (06 Sep)
What to do
  • ~196,500 MikroTik are exposed worldwide — check your own version.

last 60 dispatches · spectrum

Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5. Successful attacks date to at least September 2. …

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected