home.social

#mikrotik — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #mikrotik, aggregated by home.social.

  1. Hackers Exploit MikroTik Router Flaws to Hijack Devices

    Hackers are actively exploiting vulnerabilities in MikroTik RouterOS, using a two-step attack dubbed "MikroTrick" to hijack devices, warns Poland's Computer Emergency Response Team. The team has confirmed that the critical severity flaws, tracked as CVE-2026-67276 and CVE-2026-86060, are being used in real-world attacks.

    osintsights.com/hackers-exploi

    #Mikrotik #Routeros #Mikrotrick #EmergingThreats #SupplyChain

  2. In a nutshell, IF you’ve removed the default #MikroTik firewall or you’ve opened up SSH login to the entire world you’re at risk. One Reddit user has reported over a dozen of their routers were compromised on 2nd Sept. None of those devices had a firewall configured to block access to any management ports. For anyone who’s been on one of my MTCNAs you’d know best practise already. This is really basic stuff here guys. #MikroTrick infosec.exchange/@securityaffa

  3. #MikroTik RouterOS: #Schwachstellen werden ausgenutzt, updaten

    Kritische Sicherheitslücken in MikroTik RouterOS werden ausgenutzt (Sept. 2026)

  4. Krytyczne luki w MikroTiku, umożliwiające przejęcie urządzenia przez SSH. Łatajcie się pilnie.

    Chodzi o krytyczne podatności, które są aktywnie wykorzystywane przez atakujących, a szczegóły luk są wręcz… nieprawdopodobne. Cytaty za CERT Polska, który zgłosił do MikroTika luki: W skrócie – można dostać się na Mikrotiki z poziomu Internetu, bez jakiegokolwiek uwierzytelnienia… Łatajcie się. ~ms

    #WBiegu #Iot #Mikrotik #Podatność #Ssh

    sekurak.pl/krytyczne-luki-w-mi

  5. Krytyczne luki w MikroTiku, umożliwiające przejęcie urządzenia przez SSH. Łatajcie się pilnie.

    Chodzi o krytyczne podatności, które są aktywnie wykorzystywane przez atakujących, a szczegóły luk są wręcz… nieprawdopodobne. Cytaty za CERT Polska, który zgłosił do MikroTika luki: W skrócie – można dostać się na Mikrotiki z poziomu Internetu, bez jakiegokolwiek uwierzytelnienia… Łatajcie się. ~ms

    #WBiegu #Iot #Mikrotik #Podatność #Ssh

    sekurak.pl/krytyczne-luki-w-mi

  6. Krytyczne luki w MikroTiku, umożliwiające przejęcie urządzenia przez SSH. Łatajcie się pilnie.

    Chodzi o krytyczne podatności, które są aktywnie wykorzystywane przez atakujących, a szczegóły luk są wręcz… nieprawdopodobne. Cytaty za CERT Polska, który zgłosił do MikroTika luki: W skrócie – można dostać się na Mikrotiki z poziomu Internetu, bez jakiegokolwiek uwierzytelnienia… Łatajcie się. ~ms

    #WBiegu #Iot #Mikrotik #Podatność #Ssh

    sekurak.pl/krytyczne-luki-w-mi

  7. Krytyczne luki w MikroTiku, umożliwiające przejęcie urządzenia przez SSH. Łatajcie się pilnie.

    Chodzi o krytyczne podatności, które są aktywnie wykorzystywane przez atakujących, a szczegóły luk są wręcz… nieprawdopodobne. Cytaty za CERT Polska, który zgłosił do MikroTika luki: W skrócie – można dostać się na Mikrotiki z poziomu Internetu, bez jakiegokolwiek uwierzytelnienia… Łatajcie się. ~ms

    #WBiegu #Iot #Mikrotik #Podatność #Ssh

    sekurak.pl/krytyczne-luki-w-mi

  8. Krytyczne luki w MikroTiku, umożliwiające przejęcie urządzenia przez SSH. Łatajcie się pilnie.

    Chodzi o krytyczne podatności, które są aktywnie wykorzystywane przez atakujących, a szczegóły luk są wręcz… nieprawdopodobne. Cytaty za CERT Polska, który zgłosił do MikroTika luki: W skrócie – można dostać się na Mikrotiki z poziomu Internetu, bez jakiegokolwiek uwierzytelnienia… Łatajcie się. ~ms

    #WBiegu #Iot #Mikrotik #Podatność #Ssh

    sekurak.pl/krytyczne-luki-w-mi

  9. Attackers Exploit MikroTik Routers via Exposed SSH

    Hackers are actively exploiting MikroTik routers with exposed SSH services to gain full control, with successful attacks dating back to at least September 2. This critical vulnerability allows attackers to bypass authentication and take control of your router, putting your entire network at risk.

    osintsights.com/attackers-expl

    #Mikrotik #SshExploitation #EmergingThreats #RouterVulnerability #CertPolska

  10. VLANs on #MikroTik are just guesswork and prayer. Especially with wifi interfaces.

  11. #Mikrotik - if you are using Mikrotik routers you should immediately upgrade to the latest version due to the undisclosed security #vulnerability in RouterOS.

    Fixes included in versions:

    * 7.25 beta 3

    * 7.24.2

    * 7.23.4

    * 6.49.21

    Vendor advisory:

    mikrotik.com/supportsec/septem

  12. RE: impulsait.com/actualizacion-de

    Atención para quienes administran equipos de red de la marca @mikrotik

    La empresa Mikrotik ha anunciado una actualización de seguridad importante en su sistema operativo. En nuestro sitio pueden encontrar una guía paso a paso cómo realizar una actualización del software de equipos Mikrotik.

    #Mikrotik #Ciberseguridad #RouterOS

  13. Actualización de Seguridad Mikrotik Septiembre 2026

    La empresa MikroTik ha detectado una vulnerabilidad de seguridad en el sistema operativo de sus equipos, llamado RouterOS y ha publicado actualizaciones con la solución en todos los canales. Esta es una actualización de seguridad importante. La mayoría de las configuraciones no corren riesgo, pero se recomienda encarecidamente actualizar. Para darles tiempo a actualizar sus sistemas, por el momento no están publicando información detallada de forma inmediata. Su dispositivo ya […]

    impulsait.com/actualizacion-de

  14. On the 22nd Sept 2026 we return to Central London to deliver a #MikroTik MTCRE training. Loads of theory, labs and practical tips and examples of how to use OSPF correctly with RouterOS. Seats still available. You can even take or retake the MTCNA exam for free as well. mikrotiktraining.co.uk/product

  15. @securitym0nkey @mikrotik My take is if the management services (especially SSH) are not able to be connected to by unauthorised sources, the device isn’t vulnerable, regardless of what version it has on it. If #MikroTik have not published more details it could also be because there isn’t anything more to be said. They have provided us with a suggested action plan and for us we now know that no action is required immediately but at the next maint window we will upgrade. Until then we will test.

  16. @securitym0nkey @mikrotik My take is if the management services (especially SSH) are not able to be connected to by unauthorised sources, the device isn’t vulnerable, regardless of what version it has on it. If #MikroTik have not published more details it could also be because there isn’t anything more to be said. They have provided us with a suggested action plan and for us we now know that no action is required immediately but at the next maint window we will upgrade. Until then we will test.

  17. @securitym0nkey @mikrotik My take is if the management services (especially SSH) are not able to be connected to by unauthorised sources, the device isn’t vulnerable, regardless of what version it has on it. If #MikroTik have not published more details it could also be because there isn’t anything more to be said. They have provided us with a suggested action plan and for us we now know that no action is required immediately but at the next maint window we will upgrade. Until then we will test.

  18. @securitym0nkey @mikrotik My take is if the management services (especially SSH) are not able to be connected to by unauthorised sources, the device isn’t vulnerable, regardless of what version it has on it. If #MikroTik have not published more details it could also be because there isn’t anything more to be said. They have provided us with a suggested action plan and for us we now know that no action is required immediately but at the next maint window we will upgrade. Until then we will test.

  19. @securitym0nkey @mikrotik My take is if the management services (especially SSH) are not able to be connected to by unauthorised sources, the device isn’t vulnerable, regardless of what version it has on it. If #MikroTik have not published more details it could also be because there isn’t anything more to be said. They have provided us with a suggested action plan and for us we now know that no action is required immediately but at the next maint window we will upgrade. Until then we will test.

  20. So after running a @prosodyim container and a #dn42 node on my #MikroTik it was only logical to also host the dn42 authoritative #DNS zone on it... using #dnsmasq 🤪

    Blog post: op-co.de/blog/posts/mikrotik_a

  21. DoH на роутере OpenWRT, Mikrotik и Asus: пошаговая инструкция от того, кто сам хостит резолвер

    Если коротко, DNS это последний открытый протокол в вашей сети, по которому провайдер (и любой джентльмен в кафе на open WiFi) видит, куда вы ходите. HTTPS закрыли, SNI потихоньку прячут через ECH, а DNS как был в плейне на 53-м порту, так в большинстве домашних сетей и остался. DoH (DNS over HTTPS) это лечит, но не на устройстве, а на роутере, чтобы один раз настроил и забыл про все смартфоны, тостеры и умные лампочки. Я три месяца пилю свой DNS-резолвер с фильтрацией и за это время насмотрелся на чужие конфиги достаточно, чтобы написать инструкцию без воды. Разберу OpenWRT, Mikrotik (RouterOS 7+) и Asus с Merlin, плюс подводные камни, в которые я лично наступил.

    habr.com/ru/articles/1035612/

    #DoH #OpenWRT #Mikrotik #RouterOS #AsuswrtMerlin #dnsmasq #httpsdnsproxy #DNSoverHTTPS #роутер #privacy

  22. In today's #fuckshit with #mikrotik. Hardware is kinda Fire.. The way you guys do shit is weird! At the very least this shit is not for rest of us. VyOS software router didn't take this much brain power to get going. I finally got my network moved over to it. I needed to add bridge, vlans, vlan interfaces, trunk ports in bridges, add interfaces and vlan interfaces to bridges, add interfaces to interfaces lists to allow firewalls shit, add address pools, then dhcp servers, and then add networks ( which are not vlans). I still have not set up PBR. And before you come at me with this, "do you even network bro bullshit"!! NO! I don't.. I'm not sure this fucking thing networks without you getting drugged in in a foreign country for your kidneys!!

    Now don't get me wrong( or get me all the way wrong)!!! The software is a POS 🤣 It's powerful, I'm sure! You just need to kill a baby unicorn goat! Then it might do what you want it to!

    #homelab #selfhosted #selfhosting #i #am #Kidding

  23. A week’s amazing camping holiday is coming to an end today. Wished we had stayed longer now. No camp provided WiFi nearby so we’ve been using the #MikroTik LHGR for 4G LTE access instead. Phone on same EE network at arms length doesn’t even register any signal at all. #BackToNature #BackToBasics #Camping but .. yeah… ok, with high speed internet 🤣