Tag: router
-
MikroTik RouterOS Vulnerabilities Actively Exploited via SSH
Attackers are actively exploiting MikroTik RouterOS flaws for unauthenticated router takeover. Here are the fixes, indicators of compromise, and post-patch checks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-mikrotik-routeros-mikrotrick-ssh-exploit/
-
âš¡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on.Elsewhere, a trusted software source delivered code that stole…
-
Daily OT Security News: September 07, 2026
Today’s selection covers IoT, OT, ICS and cyber-physical-system security developments that may affect edge networking, management platforms, industrial assets and healthcare devices. Hackers exploit new MikroTik RouterOS flaws to hijack routers Attackers are actively exploiting a chain of two MikroTik… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/daily-ot-security-news-september-07-2026/
-
MikroTik Issues Patches for Routers Amid Zero-Day Attacks
Chaining Two Flaws Leads to Full Compromise, Warn Polish Incident Responders. Latvian router-maker MikroTik has issued emergency patches in the face of in-the-wild MikroTrick attacks that chain together exploits for two zero-day vulnerabilities in the RouterOS operating system that runs MikroTik devices to obtain full, remote control of any device with SSH access enabled. First…
-
Hackers exploit new MikroTik RouterOS flaws to hijack routers
Hackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-exploit-new-mikrotik-routeros-flaws-to-hijack-routers/
-
Hackers exploit new MikroTik RouterOS flaws to hijack routers
Hackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-exploit-new-mikrotik-routeros-flaws-to-hijack-routers/
-
Hackers exploit new MikroTik RouterOS flaws to hijack routers
Hackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-exploit-new-mikrotik-routeros-flaws-to-hijack-routers/
-
Mikrotik: Über 100.000 Router sind laufenden Angriffen ausgesetzt
Tags: routerWer einen Mikrotik-Router verwendet, sollte diesen dringend aktualisieren. Angreifer nutzen Sicherheitslücken aus, um die Geräte über SSH zu kapern. First seen on golem.de Jump to article: www.golem.de/news/mikrotik-ueber-100-000-router-sind-laufenden-angriffen-ausgesetzt-2609-212701.html
-
Hackers Actively Exploiting MikroTik RouterOS MikroTrick Flaws to Take Full Control of Routers
Threat actors are actively exploiting critical vulnerabilities in MikroTik RouterOS, collectively known as MikroTrick, to compromise internet-exposed routers and gain complete administrative control. The attacks primarily target devices with SSH management access that are exposed to public networks, prompting urgent patching recommendations from MikroTik, CERT Polska, and Latvia’s national CERT.LV. On September 3, MikroTik issued…
-
Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”
MikroTik RouterOS SSH zero-day (MikroTrick chain) under active exploitation since Sept 2. Patch to 7.24.2, 7.23.5, or 6.49.21 immediately and check logs. Anyone running a MikroTik router with SSH exposed to the internet should treat it as compromised until proven otherwise. The popular cybersecurity expert Costin Raiu published a detailed technical breakdown of the active…
-
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Tags: access, attack, authentication, control, data-breach, exploit, hacker, Internet, router, serviceAttackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska’s attack warning, published on September 5.Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count…
-
TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft
Tags: credentials, cve, cyber, flaw, login, network, password, remote-code-execution, router, service, theft, update, vulnerabilityTP-Link has released security updates for two vulnerabilities found in its Archer AX55 v4 wireless router. These vulnerabilities could allow attackers on the local network to crash a key networking service, potentially execute code, or steal administrator credentials from captured login traffic. The vulnerabilities, identified as CVE-2026-18167 and CVE-2026-18330, impact the router’s EasyMesh component and…
-
TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft
Tags: credentials, cve, cyber, flaw, login, network, password, remote-code-execution, router, service, theft, update, vulnerabilityTP-Link has released security updates for two vulnerabilities found in its Archer AX55 v4 wireless router. These vulnerabilities could allow attackers on the local network to crash a key networking service, potentially execute code, or steal administrator credentials from captured login traffic. The vulnerabilities, identified as CVE-2026-18167 and CVE-2026-18330, impact the router’s EasyMesh component and…
-
China’s ‘Fire Ant’ campaign used compromised Cisco routers as platform for more attacks
A hacking operation dubbed Fire Ant “didn’t just compromise systems,” according to researchers. “It compromised the trust layer those systems depend on.” First seen on therecord.media Jump to article: therecord.media/router-hacks-fire-ant-group-china
-
China-Linked Hackers Turn Cisco Routers Into Covert Network Gateways
China-linked Fire Ant hackers compromised Cisco IOS XR routers, management hosts, and authentication systems to create covert paths into other networks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-fire-ant-hackers-cisco-ios-xr-routers/
-
Fire Ant Hackers Compromise Cisco Routers and TACACS Servers to Target Critical Infrastructure
China-nexus threat actor Fire Ant has expanded its espionage operations from VMware hypervisors to the trusted infrastructure layer, compromising Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts. Security firm Sygnia, which investigated the activity, said Fire Ant has remained active since it was first reported in 2025. The actor’s latest operations show…
-
State-linked actor targets Cisco routers for espionage
An actor known as Fire Ant has expanded its reach into trusted environments, with unique tooling and stealth. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/state-actor-cisco-routers-China-espionage/829181/
-
âš¡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
The boring parts caused most of the trouble.A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional.Elsewhere, fake apps, helpful support calls, cheap banking…
-
Chinese Fire Ant hackers turn Cisco routers into spying platforms
The researchers discovered Fire Ant’s new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/chinese-fire-ant-hackers-turn-cisco-routers-into-spying-platforms/
-
China-linked Fire Ant Hides Inside Trusted Infrastructure
Fire Ant hijacked Cisco routers, stole credentials and altered logs to hide its tracks, using trusted infrastructure to reach high-value networks. Chinese-linked cyber espionage group Fire Ant has spent the past year quietly graduating from hacking individual computers to hacking the infrastructure that connects them. Sygnia’s new report traces how the group expanded from compromising…
-
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks.Sygnia, the incident response firm that investigated the intrusion, said the actor First seen…
-
D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft
D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker on the local network to reset the administrator password and retrieve wireless configuration information, including Wi-Fi credentials. The vulnerabilities affect the non-US DIR-X1860Z hardware revision A1/V1.0 running firmware version V1.0.2.220120.165402. D-Link addressed these issues in…
-
D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft
D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker on the local network to reset the administrator password and retrieve wireless configuration information, including Wi-Fi credentials. The vulnerabilities affect the non-US DIR-X1860Z hardware revision A1/V1.0 running firmware version V1.0.2.220120.165402. D-Link addressed these issues in…
-
D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft
D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker on the local network to reset the administrator password and retrieve wireless configuration information, including Wi-Fi credentials. The vulnerabilities affect the non-US DIR-X1860Z hardware revision A1/V1.0 running firmware version V1.0.2.220120.165402. D-Link addressed these issues in…
-
Simple Router DNS Tweak Blocks Malware and Phishing Across All Connected Devices
A recent router-level DNS change is gaining attention as a method to reduce exposure to phishing pages and malware across all devices connected to a home network. Cybersecurity expert Luis Catacora has recommended replacing a router’s default DNS resolvers with Cloudflare’s malware-filtering addresses: 1.1.1.2 as the primary resolver and 1.0.0.2 as the secondary. Simple Router…
-
China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices.The implants, named SPEAKINGSTONE and DARKLANTERN by the company’s zero-day research team, are tracked as CVE-2026-74232 and CVE-2026-74233. First seen…
-
Chinese Routers Sold Worldwide Contain Backdoors
An untold numbers of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/chinese-routers-sold-worldwide-backdoors
-
Salt Typhoon Is Already Inside Encryption Doesn’t Solve the Problem
Tags: access, advisory, ai, api, china, cisa, cloud, communications, control, credentials, cyber, cybersecurity, data, defense, detection, encryption, endpoint, exploit, government, identity, infrastructure, intelligence, Internet, microsoft, network, resilience, risk, router, saas, service, software, strategy, switch, technology, theft, threat, tool<div cla COMMUNICATIONS SECURITY BRIEFING What Volt Typhoon and Salt Typhoon reveal about the next front in communications security, and why hardened transport is the missing layer Volt Typhoon and Salt Typhoon mark a deliberate shift in how state-sponsored cyber campaigns operate. Rather than chasing endpoints or applications, these actors have gone after the infrastructure…
-
Salt Typhoon Is Already Inside Encryption Doesn’t Solve the Problem
Tags: access, advisory, ai, api, china, cisa, cloud, communications, control, credentials, cyber, cybersecurity, data, defense, detection, encryption, endpoint, exploit, government, identity, infrastructure, intelligence, Internet, microsoft, network, resilience, risk, router, saas, service, software, strategy, switch, technology, theft, threat, tool<div cla COMMUNICATIONS SECURITY BRIEFING What Volt Typhoon and Salt Typhoon reveal about the next front in communications security, and why hardened transport is the missing layer Volt Typhoon and Salt Typhoon mark a deliberate shift in how state-sponsored cyber campaigns operate. Rather than chasing endpoints or applications, these actors have gone after the infrastructure…
-
Unpatched Calix router vulnerability allows remote attackers to expose home networks
First seen on scworld.com Jump to article: www.scworld.com/brief/unpatched-calix-router-vulnerability-allows-remote-attackers-to-expose-home-networks

