Feed aggregator
Even when leading 12,000 IT professionals to support 87 million consumers and 7.5 million small businesses, the tech chief at JPMorgan's consumer banking arm says being a CIO is still fun
As enterprises move beyond artificial intelligence pilots, Huawei is positioning its cloud, computing and partner ecosystem to help organisations build scalable AI platforms while maintaining control over data, models and infrastructure
Facility will develop AI-driven network automation software, strengthen local digital skills and contribute Made in Saudi innovations for global telecoms markets
MikroTik router flaws allow takeover without a password
CERT Polska warns that attackers are actively exploiting a chain of critical MikroTik RouterOS flaws to seize control of routers exposed to the internet.
Although the warning comes from Poland’s national cybersecurity response team, MikroTik routers are sold worldwide, including in the US. The vulnerabilities can affect users anywhere if their router is running a vulnerable version of RouterOS and its SSH remote-management service is accessible from the internet.
Attackers are exploiting two vulnerabilities, collectively dubbed “MikroTrick,” to take full control of vulnerable devices, CERT Polska says.
A compromised router is especially serious because it sits at the edge of your network. An intruder may be able to change DNS settings, redirect or capture traffic, create remote-access tunnels, alter firewall rules, or use the device as a foothold to attack other devices on the network.
Two of the six disclosed vulnerabilities form the chain of compromise known as MikroTrick. The first, tracked as CVE-2026-67276, is an SSH authentication-bypass flaw in the handling of RSA public keys. The second, CVE-2026-86060, is a privilege-escalation flaw involving a specially crafted username in the SSH login process.
Put simply, the first flaw lets attackers get in without a password, and the second lets them make themselves an administrator.
SSH (short for Secure Shell) is a network protocol that establishes encrypted connections between computers for secure remote access.
CERT Polska issued the warning because the patched RouterOS packages are already public, and their comparative analysis has allowed the community to reconstruct some of the flaws they fix.
How to stay safeMikroTik router owners should install the latest RouterOS security update as soon as possible. Use the router’s update mechanism or obtain the supported package directly from MikroTik. The update option should be available under Check for updates.
You should also remove public access to the router’s management services. Make sure that SSH is not accessible from untrusted networks. If remote administration is necessary, limit access to known IP addresses.
Remote management should be the exception, not the default. MikroTrick demonstrates that a strong password alone cannot protect a device from an authentication-bypass vulnerability.
MikroTik has added a detection mechanism that scans the configuration at startup for selected signs of unauthorized changes. If it finds any, RouterOS disables the recognized suspicious entries and sets the device’s Flagged status to Yes. Administrators can check this with /system/device-mode/print.
RouterOS restricts several potentially abusable functions while the device is flagged, but MikroTik stresses that the router’s full configuration still needs to be audited before the flag is cleared.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
Three Cities, 16 Years And $1 Billion Later, 'Defiant' Lucas Museum of Narrative Art Opens To Mixed Reviews
PicWish – AI photo editing for product images
Article URL: https://picwish.com/
Comments URL: https://news.ycombinator.com/item?id=49607853
Points: 1
# Comments: 0
The Computer Moves In (1983)
Article URL: https://time.com/archive/6699317/the-computer-moves-in/
Comments URL: https://news.ycombinator.com/item?id=49607830
Points: 1
# Comments: 0
Arguments in Favor of AI Fair Use
Article URL: https://kevinkelly.substack.com/p/arguments-in-favor-of-ai-fair-use
Comments URL: https://news.ycombinator.com/item?id=49607805
Points: 1
# Comments: 0
Prolog knowledge base over HTTP/JSON API, with an OpenAPI description
Article URL: https://github.com/Christopher22/charon
Comments URL: https://news.ycombinator.com/item?id=49607802
Points: 1
# Comments: 0
A Digital Duty of Care for Australia
Use the Canvas API to speed up image uploads without losing EXIF data
Article URL: https://ptrchm.com/posts/why-pixelpeeper-image-uploads-feel-fast/
Comments URL: https://news.ycombinator.com/item?id=49607760
Points: 1
# Comments: 0
Which platform to use for idea validation?
Article URL: https://proventrips.com
Comments URL: https://news.ycombinator.com/item?id=49607757
Points: 1
# Comments: 1
Howold.me – Fast, no-nonsense exact age and life stats calculator
Article URL: https://howold.me/en
Comments URL: https://news.ycombinator.com/item?id=49607744
Points: 1
# Comments: 1
the appeal
Article URL: https://sunilpai.dev/posts/the-appeal/
Comments URL: https://news.ycombinator.com/item?id=49607743
Points: 1
# Comments: 0
Ghost Imaging: Who Needs a Double Slit Anyway?
Article URL: https://sciencespectrumu.com/who-needs-a-double-slit-anyway-47b903579252?sharedUserId=r.hendriks
Comments URL: https://news.ycombinator.com/item?id=49607738
Points: 1
# Comments: 0
Nepal-Tibet disaster becomes latest victim of China's 'Clean Internet' campaign
Arch Linux on a OnePlus 12R, Powered by Denial Wayland and Flutter Compositor
Article URL: https://www.reddit.com/r/mobilelinux/comments/1w80kvt/arch_linux_on_a_oneplus_12r_powered_by_the_denial/
Comments URL: https://news.ycombinator.com/item?id=49607677
Points: 1
# Comments: 0
A team-oriented UI for Beads
Article URL: https://www.npmjs.com/package/beadcyte
Comments URL: https://news.ycombinator.com/item?id=49607645
Points: 1
# Comments: 0
Official tutorial how to be crazy, hehe [video]
Article URL: https://www.youtube.com/watch?v=xIn_wS2zwDk
Comments URL: https://news.ycombinator.com/item?id=49607635
Points: 1
# Comments: 0
