CERT Polska says attackers are actively exploiting two MikroTik RouterOS flaws in a chain it calls MikroTrick, and MikroTik has shipped fixed builds for affected devices. The attacks target routers with SSH exposed to the internet and can end in full device takeover.
The first bug lets RouterOS accept an SSH login without the private key because it checks only part of an RSA public key. The second turns that foothold into full admin access with a crafted username, so the compromise reaches the router’s control plane, not just a single account.
That matters because the fallout can persist in configuration objects, not just the login session. If your RouterOS devices sit on a public SSH surface, the exposure is the whole edge box and any unknown users, scripts, scheduler tasks, proxy servers, or tunnels left behind after patching.