Skip to main content

Share story

Security Infrastructure

Analysis identifies two flaws behind exploited MikroTik router takeover chain

Analysis identifies two flaws behind exploited MikroTik router takeover chain Image: Primary
CERT Polska has identified the two RouterOS SSH flaws behind a previously reported attack that can give intruders administrative control of exposed MikroTik routers without completing authentication. One flaw lets a connection reach the command stage early; the other lets a crafted username influence the login program's privilege settings. Attack logs date to at least September 2, before MikroTik released fixes the next day. CERT Polska's latest analysis explains how the flaws work together and reports successful account creation on affected devices. The chain requires SSH to be reachable by the attacker, and no authoritative count of compromised devices has been published.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Products
Products

Bird.com raises $450 million in JPMorgan-led debt financing

Bird.com, a customer messaging company, raised $450 million in debt financing led by JPMorgan Chase & Co., Bloomberg reported. The company is seeking to return cash to its investors and employees. The transaction adds debt capital...

Capital Infrastructure
Capital Infrastructure

Hubble Network raises $200 million for satellite Bluetooth network

Satellite startup Hubble Network raised $200 million in a new funding round, Bloomberg reported, taking its valuation to $1.6 billion. The company is working on a network of spacecraft intended to provide global Bluetooth connecti...

Security Infrastructure
Security Infrastructure

F5 patches exploited BIG-IP APM flaw as U.S. agencies face Friday deadline

F5 has released security updates for a critical BIG-IP APM flaw that it says attackers have exploited to run code remotely. BIG-IP APM manages access to organizational networks and applications. The vulnerability affects configura...

Infrastructure AI
Infrastructure AI

German and Dutch agencies launch €40 million AI chip design challenge

Germany's SPRIND and the Netherlands' NADI have launched a joint €40 million challenge to fund European AI chip design. The agencies plan to select seven teams for an initial stage, awarding each €2.6 million, then advance three t...

Robotics Capital
Robotics Capital

Tekever reaches first close of funding round targeting $580 million

Portuguese surveillance drone developer Tekever has reached the first close of a funding round targeting $580 million, Bloomberg reports. The company is seeking acquisitions following that close. The $580 million figure is the tar...