Skip to content

Blog

MikroTrick: the SSH flaw letting attackers own MikroTik routers without a password

MikroTrick: the SSH flaw letting attackers own MikroTik routers without a password

Section titled “MikroTrick: the SSH flaw letting attackers own MikroTik routers without a password”

Attackers are taking over MikroTik routers with no password at all. Poland’s CERT agency (CERT Polska) confirmed that a chain of two RouterOS flaws, named MikroTrick, is being exploited against devices whose SSH service is reachable from the public internet (BleepingComputer). Exploitation began around September 2, one day before MikroTik shipped patched builds on September 3 (SOCPrime). On September 10, CISA added both CVEs to its Known Exploited Vulnerabilities catalog (Decryption Digest). If you run MikroTik gear, this is the story to act on today.

CERT Polska disclosed six RouterOS vulnerabilities on September 5 (eSecurityPlanet). Two of them chain together to hand an attacker full administrative control.

CVECVSSWhat it does
CVE-2026-672769.2SSH public-key authentication bypass. RouterOS compares only the key type and RSA modulus, not the full key. An attacker who knows a username and its key’s public modulus can forge a different key and log in without the private key (SOCPrime).
CVE-2026-860609.2Privilege escalation via a specially crafted username during SSH login. The crafted username manipulates the session policy so the attacker gets full administrative privileges (BleepingComputer).

The first flaw gets the attacker in. The second makes them an administrator (Malwarebytes). No credentials required, as long as SSH is exposed to the internet (BleepingComputer).

The other four flaws cover the bandwidth-test service, X.509 certificate validation, SSH authentication state, and the WebFig management interface (eSecurityPlanet). CERT Polska highlighted CVE-2026-67277, a bandwidth-test flaw rated CVSS 8.8, because it lets an unauthenticated attacker leak kernel memory or crash the router (BleepingComputer).

CERT Polska found roughly 122,500 MikroTik devices with SSH exposed to the public internet as of September 5 (daily.dev). CERT Polska confirmed the chain in its advisory. “We have obtained confirmation that the attackers are exploiting this combination of vulnerabilities to take full control of devices whose SSH service is accessible from public networks” (BleepingComputer).

A compromised router is not just a broken box. It sits at the edge of your network. An attacker who owns it can change DNS settings, redirect or capture traffic, and create remote-access tunnels. It can also alter firewall rules or serve as a foothold to attack other hosts on the network (Malwarebytes). Those are the same capabilities a cautious defender would refuse to hand to anyone.

There is a turnaround worth noting: CERT Polska accelerated the research with OpenAI’s GPT-5.5-cyber and GPT-5.6-sol models, with human researchers directing and validating the work (BleepingComputer). AI-assisted vulnerability research is now production practice at national CERTs, and it shortens the window between disclosure and exploit (daily.dev). That window is your patch deadline, and it is getting smaller.

MikroTik released patched builds on September 3, and CERT Polska validated them (BleepingComputer):

BranchFixed version
RouterOS 6 (long-term)6.49.21
RouterOS 7 (long-term)7.23.4
RouterOS 7 (stable)7.24.2
RouterOS 7 (beta)7.25beta3

MikroTik later released 7.23.5 to fix an unrelated IPv6 DHCP regression (daily.dev). The vulnerable ranges are RouterOS 6.0.0 through below 6.49.21, RouterOS 7.0.0 through below 7.23.4, and RouterOS 7.24 through below 7.24.2 (daily.dev). If you track which branch you run, the update path is short.

The patched firmware also adds a compromise-detection mechanism. At startup it looks for known signs of unauthorized configuration changes, disables malicious entries, and logs a critical warning (BleepingComputer). After updating, check /system/device-mode/print for a “Flagged” marker, and look for unknown users, scripts, or tunnels (SecureTechIn, 2026).

  1. Do not expose SSH to the internet. MikroTik recommends closing SSH to untrusted networks and using a VPN such as WireGuard for remote administration (daily.dev). Management planes belong behind the perimeter, not on it.
  2. Patch the day fixes ship, not the day exploits ship. Exploitation started one day before patches existed (SOCPrime). Treat every patch as a race.
  3. Treat a compromised edge device as a full incident. Assume the attacker changed DNS, firewall rules, and tunnels. Rebuild or wipe the device, rotate every credential it touched, and re-check the rest of the network (Malwarebytes).
  4. Add network gear to your vulnerability inventory. Your CVE feed should list routers, firewalls, and switches, not just servers and containers. This chain hit devices most teams never patch automatically.
  5. Assume the AI-assisted disclosure cadence is the new baseline. When national CERTs use frontier models to find flaws, the gap between public disclosure and working exploit shrinks (daily.dev). Your automation must shrink with it.

MikroTrick is the pattern for 2026: a cryptographically subtle auth bypass, a privilege escalation, and internet-exposed management ports turned into full device takeover in days. The fix is known, the versions are clear, and the checks are documented (eSecurityPlanet). The only open question is whether your fleet is already inside the exposed count. Close the port, ship the patch, and run the post-update checks. That is the whole job, and it is urgent (Decryption Digest).

Slow the frontier: Anthropic's three-step plan to pace the AI race

Slow the frontier: Anthropic’s three-step plan to pace the AI race

Section titled “Slow the frontier: Anthropic’s three-step plan to pace the AI race”

On September 12, Anthropic CEO Dario Amodei asked AI companies to slow the pace at which they improve model capabilities (Reuters). He published the call as an essay and outlined a three-step framework to create more time to manage risk. Reuters carried it as the week’s leading AI story, and OpenAI CEO Sam Altman endorsed part of the plan the same day (The Nation Thailand). This is a governance moment, and it changes how you buy and evaluate the models you run.

Amodei’s central request is deliberate. Labs should moderate how fast they push model capabilities forward, not stop training outright.

“We must slow the pace at which we improve the capabilities of AI models. Progress will still seem fast, and we must make wise use of the time we gain,” Amodei wrote (Reuters).

He stressed that he is not seeking an end to model training or technical advances (The Nation Thailand). He wants enough time to align systems with safety objectives and to let outside evaluators verify the safeguards (The Nation Thailand). Axios reported Amodei warned of potentially devastating consequences within months if the pace stays unchecked (Axios).

The framework rests on three parts (The Nation Thailand).

  1. Independent scrutiny inside labs. Anthropic has committed to hosting independent evaluators inside the company, with ongoing access to its tools and internal risk-assessment processes (The Nation Thailand). Amodei urged other leading developers to adopt the same approach. OpenAI’s Sam Altman backed the idea on September 12, committing to independent evaluators with employee-like access (The Nation Thailand).
  2. Common industry standards. Amodei called for voluntary agreements on safety standards and limits on uncontrolled development (The Nation Thailand). A shared floor that every lab meets beats a race to the edge.
  3. International coordination. Amodei argued that coordinated restraint among democratic countries must preserve the US technological lead over China (The Nation Thailand).

The call did not arrive in a vacuum. It followed reporting on how Claude was misused, and Moneycontrol linked the slowdown push directly to that report (Moneycontrol). Reuters reported that OpenAI executives had earlier said leading labs should be ready to coordinate a voluntary slowdown when necessary to build confidence in safety measures (The Nation Thailand).

For an operator, the signal is not ivory-tower policy. It is supply-chain and risk math.

  • Independent evaluation becomes a buying criterion. If Anthropic hosts outside evaluators with ongoing access, ask what checks your vendor runs before you trust a model with production prompts (Axios).
  • Self-hosted models give you an exit. A model you can run and verify yourself does not hinge on one lab’s pace or policy decision. Open weights remain your escape hatch when a vendor shifts.
  • Vendor concentration is now a governance risk. When one lab can unilaterally slow a frontier or change terms, your architecture should not depend on it.
  • Verification is your job too. The industry call for more time to check the work is a reminder that you still own review, guardrails, and a rollback path for anything that ships itself.

The frontier is not getting slower. Amodei said progress would still seem fast at a measured pace (Reuters). The shift is that the frontier labs now treat checking the work as a first-class requirement, not an afterthought. Adopt the same standard for the models you run in production, and you are ahead of the change.

Smaug open weights: self-improving agents at 10-100x lower cost

Smaug open weights: run self-improving agents at 10-100x lower cost

Section titled “Smaug open weights: run self-improving agents at 10-100x lower cost”

The biggest cost in enterprise AI is not the model. It is the loop: the agent that plans, calls tools, checks its work, and runs again until the job is done. On September 10, Abacus.AI released Smaug, a line of three open-weight models tuned for that long-running agentic loop (Abacus.AI press release). The company says the technique raises agentic-loop performance by 15-20% without raising cost, at prices 10-100x lower than frontier models from Anthropic and OpenAI (Abacus.AI press release). Open weight means the model and the technique are something you can own and run yourself.

Smaug is not one model. It is one fine-tuning technique applied three ways (Unite.AI).

ModelBaseJobSize / detail
Smaug AgenticMoonshot Kimi K3flagship self-improving agentsMoE, 2.8T total / 104B activated params, 1,048,576-token context (Unite.AI)
Smaug FlashDeepSeek V4 Flash 0731personal agents, messaging appsfixes long-context tool-use “spins and confusion”; WhatsApp, Telegram, Slack (Unite.AI)
Smaug Miniopen baseenterprise chatbots, light reasoning27B, multimodal, fine-tunable on your data (Morningstar / PR Newswire)

Smaug Agentic, the largest, is a supervised fine-tune of Moonshot AI’s Kimi K3, a mixture-of-experts model with 2.8 trillion total parameters, 104 billion activated, and a 1,048,576-token context window (Unite.AI). The fine-tune changes no architectural parameters, and it ships under the Kimi K3 license inherited from the base model (Unite.AI). All three models are open-weight on Hugging Face and available through Abacus’s RouteLLM API (Unite.AI).

A long-running agent loop repeats four steps until the task is done: read intent, call a tool, observe the result, then decide the next action. On a frontier model, each pass burns tokens at API rates. The loop fails when the model “spins” and re-fires the same action, or loses the thread in a long tool-use session. Smaug targets that failure point directly. Abacus says the flash variant removes the base model’s spins and confusion in long-context tool use, without losing its cost and speed profile (Unite.AI).

Self-improvement is the second half. Because you can host the model and fine-tune it on your own data, the agent can be retrained on the outcomes it produces, closing the gap between a generic assistant and a tool that knows your systems (Morningstar / PR Newswire).

The pitch is not faster answers. It is control over where the model runs and what it costs.

  • Data stays in your VPC. Abacus says enterprises can host Smaug inside their own cloud VPC, with full control over the data and the hosting location (Abacus.AI press release). No customer prompt crosses your boundary to an external API.
  • Cost scales with open weights. The company frames the price gap as 10-100x against frontier API models (Abacus.AI press release). For a loop that runs for hours, that multiple decides whether the workload is viable.
  • Fines-tuning is a real option. Smaug Mini is built to be further tuned on enterprise data (Morningstar / PR Newswire). You are not locked to a vendor’s weights.

Two caveats are worth stating plainly. Performance numbers come from Abacus’s own announcements, not from an independent benchmark (HPCwire). And a self-improving agent still needs supervision: it will act, so you need review, guardrails, and a rollback path, exactly as you would for any code that ships itself.

  1. Measure your agent-loop cost per completed task, not per token. A 10-100x gap changes what you can afford to automate (Abacus.AI press release).
  2. Treat open-weight hosting as the default for data-bound agents. A VPC-hosted model never leaks prompts to a third party (Abacus.AI press release).
  3. Verify vendor claims against an independent benchmark before you commit (HPCwire’s coverage notes the announcement framing) (HPCwire).
  4. Budget for supervision. Self-improving agents change the game, but they are still code that runs on your infrastructure.

The shift here is quiet and practical. It is not a smartest-model race. It is a cost and custody race: run agents that keep your data, at a price that makes long-running loops boring. That is the kind of boring DevOps can confidently run in production.

Cisco FMC CVSS 10.0 bypass is exploited in the wild: Sandworm and ransomware crews are in

Cisco FMC CVSS 10.0 bypass is exploited: take the management plane off the internet

Section titled “Cisco FMC CVSS 10.0 bypass is exploited: take the management plane off the internet”

The device that configures every firewall on your network is itself compromised. On September 9, Cisco Talos said three threat crews are actively exploiting CVE-2026-20079, a CVSS 10.0 authentication bypass in Cisco Secure Firewall Management Center (FMC) (Cisco Talos). The crews run a web shell, a Java command executor, Sandworm’s Cyclops Blink, and Qilin ransomware through the same console (BleepingComputer). This is not a theory. This is the management plane of your firewall fleet, hit where it cannot defend itself.

CVE-2026-20079 lets an unauthenticated remote attacker bypass login controls entirely (Cisco Talos). The flaw starts in a system process created when the FMC boots. If no legitimate user claims the resulting session, an attacker can hijack it and walk in as that user (Cyber Security News).

Cisco disclosed the flaw on March 4, 2026 (SOCRadar). Cisco released fixes on July 29, 2026 for customer-managed FMC (BleepingComputer). Security teams have had weeks to patch. Cisco said in August its team became aware of active exploitation, while indicators in a July advisory point to activity on July 23 (BleepingComputer).

The second bug, CVE-2026-20316, is a static credential issue with a CVSS score of 5.3. Alone it offers limited access. Chained with the bypass, it helps an attacker climb to full control (Cyber Security News). CISA added it to the Known Exploited Vulnerabilities catalog in late July 2026 (The Hacker News).

Talos tracks three attack clusters in the same management plane (Cisco Talos).

  1. UAT-12197: web shell plus credential theft. They plant a JSP web shell inside the FMC Tomcat webroot, then drop an executable archive command executor named cmd.jar (Cyber Security News). The chain sips authentication data and credentials from the compromised box.

  2. UAT-11823: Sandworm (GRU Unit 74455). The Russian state group swaps the license file for a malicious copy, then executes it as root through the legitimate package_info.pl utility. The file is actually a Makeself package that sets up a Netcat-based reverse shell to its command-and-control server (Cisco Talos). It collects configuration data from every managed firewall into archives, then installs a modular Linux implant: Cyclops Blink, the family US and UK agencies previously tied to Sandworm (Cisco Talos). This variant persists through init directories, resolves its command server through DNS over HTTPS, and harvests credentials (Cisco Talos).

  3. UAT-11988: Qilin ransomware. A third crew logs in with the static credentials from CVE-2026-20316, maps the environment, steals more credentials, and builds the target list it will later encrypt (Cisco Talos). It then deploys the Qilin ransomware family across the fleet (The Hacker News).

One console controls every firewall rule, every VPN policy, every network access boundary on the fleet (SecurityWeek). Whoever sits in FMC does not break one firewall. They get to re-draw the whole network’s rule base.

FMC is the single place your firewall rules are pushed from. A compromise there does not just read secrets. It can modify the rules the whole perimeter enforces (Alvaka). An attacker can add their own rules, delete yours, or hand your wire directly to their callbacks.

FCEB agencies must patch known exploited FMC before September 12, 2026, per CISA’s KEV catalog (BleepingComputer). CVE-2026-20079 is the third FMC vulnerability CISA added to KEV in 2026, so this family of flaws keeps drawing attackers (SecurityWeek). No work-around fully covers the issue. The only fix is the patch (SOCRadar).

Cisco has hot fixes for every supported release branch, including 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 (SOCRadar). Apply them. This is the only full fix.

1.Patch FMC this week. Apply the hotfix to every FMC instance, even isolated ones. The attacker does not care about your change window (Help Net Security). 2.Pull the management interface off the public internet. Restricting which networks can reach FMC materially reduces the chance of exploitation (SecurityWeek). FMC never needs to be a public endpoint. 3.Treat Friday’s date as the industry floor. Even if you are not federal, apply the KEV deadline to your own fleet (BleepingComputer). 4.Sweep for the artifacts. Look for a JSP web shell in the Tomcat webroot, a cmd.jar executable, a tampered license file, and a Netcat-based reverse shell spawned via the package utility (Cyber Security News). 5.Reset the admin credential chain. Assume sessions. Rotate FMC admin accounts, change static credentials, and check every identity provider that can log in to it (Cyber Security News). 6.Audit the managed config. Export every firewall policy and diff it against the last known-good baseline. A rule you did not write lives somewhere (Help Net Security).

A perfect 10.0 bug in your firewall control plane is being actively exploited by three crews today. Sandworm’s implant and Qilin ransomware both route through FMC. The fix has existed since July and the CISA deadline lands tomorrow. Patch the box, and take the management console itself off the internet (Cisco Talos).

Microsoft's biggest Patch Tuesday ever: 974 fixes, two live zero-days

Microsoft’s biggest Patch Tuesday ever: 974 fixes, two live zero-days

Section titled “Microsoft’s biggest Patch Tuesday ever: 974 fixes, two live zero-days”

Microsoft shipped its largest security update ever on September 8, 2026(The Hacker News). The September batch covers 974 vulnerabilities across Windows, Office, SQL Server, and developer tools(The Hacker News). Vendors report different totals because they count different scopes. Malwarebytes counts 964 customer-patchable flaws, with 104 rated critical and 860 rated important(Malwarebytes). Two of those flaws are already exploited in the wild. This is not a “patch everything today” story. It is a triage story.

Both exploited flaws are local privilege-escalation bugs. Each lets an attacker who already has a foothold climb to SYSTEM(Malwarebytes). SYSTEM access turns one compromised account into full machine control. Neither flaw gives remote access by itself, but both remove the last barrier between a beachhead and domain-wide movement(Malwarebytes).

CVE-2026-85880 — Windows ALPC. This is a heap-based buffer overflow in Windows Advanced Local Procedure Call (CVSS 7.8(The Hacker News). Microsoft says an attacker who can run code in a low-privilege AppContainer can exploit the flaw locally, escape the sandbox, and elevate privileges on the affected system(The Hacker News). No additional user interaction is required(The Hacker News). Volexity and Proofpoint reported the bug(The Hacker News).

CVE-2026-81963 — Windows Update Stack. This is an improper link resolution (“link following”) flaw, CVSS 7.8(The Hacker News). The stack can follow a malicious link and overwrite a system component with an attacker-controlled impostor(The Hacker News). Per Tenable, this is the first Windows Update Stack privilege-escalation flaw exploited as a zero-day since 2022(The Hacker News). All supported Windows versions receive a patch(The Hacker News). An Airbus Helicopters researcher and Microsoft Threat Intelligence Center reported the flaw(The Hacker News).

CISA has already moved. Both CVEs sit on CISA’s Known Exploited Vulnerabilities catalog(The Hacker News). US federal civilian agencies must apply the fixes by September 22, 2026(The Hacker News). Private-sector teams should treat that date as a floor, not a ceiling.

The server-side fixes that deserve the next slot

Section titled “The server-side fixes that deserve the next slot”

Microsoft patched nine Exchange Server vulnerabilities this month(Petri). One of them, CVE-2026-55007 is a double-free flaw that lets an unauthenticated attacker run code over a network(The Hacker News). An email with a malicious Visio attachment can trigger it(Petri). That is an email-delivered unauthenticated RCE against a mail server. Patch Exchange before anything else in the messaging path.

SQL Server carries a 9.6-CVSS injection flaw, CVE-2026-65669(Petri). An unauthorized attacker can elevate privileges over a network when a user submits instructions through SQL Copilot(Petri). The AI assistant becomes an attack path. Remote Desktop Services carries a 9.8-CVSS RCE bug, CVE-2026-69525(Petri). SharePoint carries an 8.8 authorization flaw that attackers can use to execute code over an enterprise network(Petri).

Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, said many of the disclosed flaws have “wormable” properties( They need zero user interaction and can jump across network-connected hardware(Times of India).

The September count tops every previous Patch Tuesday(Malwarebytes). More than 110 of the flaws carry critical severity ratings(The Hacker News). Microsoft counted 161 fixed flaws in May, 220 in June, 663 in July, and 457 in August(The Hacker News).

Dustin Childs says AI-assisted discovery is a big part of the trend: “AI-assisted vulnerability discovery shows no signs of slowing down” (CyberScoop). He adds a caveat:“However, we have not seen a correlating spike in active exploits —yet” (CyberScoop).

Jack Bicer, director of vulnerability research at Action1, said:“At this scale, the challenge is not simply getting through the patch list but knowing what needs attention first” (The Hacker News).

1.Patch the KEV zero-days first. Apply Windows updates that cover CVE-2026-85880 and CVE-2026-81963 on every endpoint. The September 22 deadline binds federal agencies, but adopt it as the industry tempo(The Hacker News).

2.Inventory exposure before you schedule. Find every Exchange Server, SQL Server, Remote Desktop host, and SharePoint farm. An unauthenticated RCE in any of them is emergency-class(Petri).

3.Batch Exchange and SQL Server fixes into planned windows. CVE-2026-55007 rides in via an email, so one malicious message can reach an unpatched server(Petri). Schedule with rollback plans and test paths for both services(Petri).

4.Watch exploitation chatter, not just patch status. The fix volume is rising faster than observed exploitation(CyberScoop). Track CISA’s KEV catalog plus your EDR telemetry for post-patch attempts(The Hacker News).

5.Gate your AI assistants’ data-store access. SQL Copilot is a new instruction path into SQL Server(Petri). Audit which AI tools can reach production data stores, and apply least privilege to their actions(Petri).

September’s Patch Tuesday is the largest on record(Malwarebytes). Two zero-days are live now,and server-side RCEs crowd the queue(The Hacker News). Teams that win this month triage by exposure, not by list length. Patch the two exploited privilege bugs first. Then close Exchange, SQL Server, RDS, and SharePoint. Then watch for the next wave(CyberScoop).