Technology newsroom
π¨ URGENT WARNING! Critical MikroTik Vulnerability Actively Exploited β Admins Advised to Update and Check Immediately
Urgent warning: MikroTik administrators should update RouterOS immediately after a critical vulnerability was found to be actively exploited by hackers to bypass SSH and create new user accounts for persistent access.
π Key Takeaways:
- A Critical vulnerability has been found in MikroTik devices, allowing hackers to bypass SSH authentication.
- Reports indicate that this vulnerability is being actively exploited on a widespread scale, with attackers creating new user accounts to embed themselves in systems.
- MikroTik has released a patch for the vulnerability. System administrators are strongly advised to update their RouterOS firmware as soon as possible and check for signs of intrusion.
The SANS Internet Storm Center team has issued a warning about a critical security vulnerability in MikroTik devices, which are widely used in many organizations. This vulnerability is highly severe as it allows malicious actors to bypass SSH authentication and gain remote control of the devices.
Most concerning is that this vulnerability is no longer theoretical; it has been confirmed to be actively exploited by hackers targeting unpatched devices on a widespread scale. The primary tactic of attackers after successfully breaching a system is to create new user accounts to establish a backdoor, maintaining access to the device even if administrators later apply patches.
π‘οΈ Recommendations for System Administrators:
As this vulnerability is currently being heavily exploited, it is recommended to operate under the principle of βAssume Compromiseβ β pre-assume your device may have been compromised if it is connected to the internet and has not yet been updated.
1. Update RouterOS: Update the RouterOS firmware on all MikroTik devices to the latest version as soon as possible.
2. Check User Accounts: Use the `/user print` command to check the list of all user accounts on the device, and immediately delete any unknown or suspicious accounts.
3. Check Logs: Review system logs for unusual login activities or connections from unfamiliar IPs.
4. Change Passwords: For maximum security, consider changing the passwords for all users on the system.
Updating the patch alone may not be sufficient. Thoroughly checking for signs of intrusion, particularly inspecting for newly created user accounts, is crucial to ensure your system's long-term security against unauthorized access.
π¬ System administrators, have you checked your MikroTik devices? Did you find any strange accounts or suspicious traces? Feel free to share your experiences!