Posted in Commentary with tags on September 9, 2026 by itnerd

Following Microsoft’s September 2026 Patch Tuesday security updates, a security researcher uncovered a new Microsoft Defender zero-day exploit named “ShieldCrash,” a bypass for the recently patched ShieldBreak Defender privilege escalation.

Ensar Seker, CISO at cybersecurity threat intelligence company SOCRadar, provided the following comments:

“ShieldCrash is concerning not simply because it affects Microsoft Defender, but because it appears to expose a recurring weakness in how this attack path has been remediated. When researchers can bypass successive fixes for RoguePlanet and ShieldBreak, it suggests the underlying security boundary or attack surface may require a more comprehensive redesign rather than another narrowly targeted patch.

It is important, however, to describe the current impact accurately. The publicly released proof of concept reportedly performs an arbitrary file read under the SYSTEM security context on fully patched Windows systems. That could expose highly sensitive files that an ordinary user cannot access, including configuration data, credentials or other secrets. Based on the information currently available, it does not yet provide an attacker with a full SYSTEM shell or arbitrary write capability. Nevertheless, privileged file disclosure can become an important component of a larger attack chain.

Organizations should not disable Defender as a reaction. Security teams should closely monitor Microsoft’s guidance and Defender intelligence updates, ensure tamper protection is enabled, restrict local execution and administrative access, and hunt for suspicious processes interacting with protected files through Defender-related mechanisms. Because proof-of-concept code is now public, defenders should assume attackers are examining it for ways to expand the primitive into credential theft, persistence or full privilege escalation. Microsoft should also assess the complete vulnerability class and related code paths, not only the specific condition demonstrated by this latest proof of concept.”

Microsoft responded with warnings of legal action against anyone engaging in “malicious activity causing real harm” to its customers, prompting many to believe that the company was directly threatening the security researcher.

But the fact is that the cat is out of the bag so to speak. Therefore Microsoft will need to deal with it. So lets see if they actually deal with it or not.

Parallel Works and CoreWeave to Accelerate DARPA Biological Research with Fully Managed AI Cloud Environment    

Posted in Commentary with tags on September 9, 2026 by itnerd

Parallel Works, Inc. and CoreWeave, Inc. today announced the deployment of a managed AI and high-performance computing platform for the Defense Advanced Research Projects Agency (DARPA) Network of Optimal Dynamic Energy Signatures (NODES) program.

The managed platform, delivered through Parallel Works’ ACTIVATE control plane and built on CoreWeave’s AI cloud platform, provides researchers with immediate access to the large-scale computing, orchestration software, and technical support required for advanced biological modeling and AI, without the delays and complexity of building and managing infrastructure.

The rapid adoption of AI is reshaping scientific research. Delivering AI cloud infrastructure, however, can take months, which can delay research and consume technical resources. By delivering a fully managed environment, Parallel Works and CoreWeave allow researchers to train AI models and run complex simulations within days rather than weeks or months.

NODES addresses complex challenges in the dynamics of biological systems, work that requires large-scale, dependable computing resources. Rapid access to dedicated GPU resources enables program performers to pursue simulation and modeling campaigns without delays associated with accessing and managing infrastructure.

Researchers access the environment through a single sign-on, with the ACTIVATE platform combining direct support, dedicated compute, unified orchestration and operational visibility:

  • End-to-end support: Parallel Works operates the environment for DARPA through its ACTIVATE platform, which handles user onboarding, identity and access, provisioning, scheduling, and reporting, with around-the-clock direct-to-expert support for both the platform and researcher applications.
  • Dedicated compute capacity: A dedicated reservation on NVIDIA HGX H100 systems, enterprise-scale storage, and high-speed NVIDIA Quantum InfiniBand networking. Parallel Works ACTIVATE divides the reservation across the NODES research teams, so each team holds a guaranteed allocation and can draw on shared capacity when it is available.
  • Unified orchestration: Parallel Works ACTIVATE enables DARPA researchers to access SUNK and CoreWeave Kubernetes Service (CKS) uniformly from a single platform. SUNK, CoreWeave’s Slurm on Kubernetes offering, enables researchers to run workloads of different kinds and sizes efficiently in the same underlying compute environment. ACTIVATE manages the accounts, allocations, and sharing policies that determine how the research teams use those resources.
  • Operational visibility: Parallel Works ACTIVATE provides the program and each research team usage and utilization reporting across the environment, while CoreWeave’s observability stack monitors the health of the underlying fleet, so issues are caught at the infrastructure layer before they cost time on a multi-week run.

More information on The Network of Optimal Dynamic Energy Signatures (NODES) program DARPA NODES can be found here: https://www.darpa.mil/research/programs/nodes

Other World Computing Expands USB4 Products Portfolio – Launches OWC USB4 Hub and USB4 40Gb/s Active Optical Cables in 3-Meter and 5-Meter Lengths

Posted in Commentary with tags on September 9, 2026 by itnerd

Other World Computing today announced the expansion of its USB4 product portfolio with the addition of the OWC USB4 Hub and USB4 40Gb/s Active Optical Cables in 3-Meter and 5-Meter Lengths.

The OWC USB4 Hub is designed for creative professionals, heavy storage users, and hybrid workers, as well as anyone using a modern laptop as their primary computer who wants full desktop connectivity without the clutter. With up to 40Gb/s of total bandwidth, one USB4 cable connects their laptop to fast external storage, accessories, and an HDMI 2.1 display while delivering up to 81W of charging – eliminating the constant juggling of ports, adapters, dongles, and chargers. In short, it gives users the portability of a laptop without connectivity compromises when they sit down to work.

OWC USB4 Hub Key Features:

  • One Cable Desk Setup: Up to 40Gb/s of total bandwidth, high resolution and high refresh rate display output, and industry leading charging, all through a single USB4 cable.
  • Blazing Fast USB4 Speed: Two USB4 ports deliver the performance to keep up with your workflow. Now you can simultaneously pull files from a card reader while using an SSD to back up files.
  • Native HDMI 2.1 Connectivity: With a built-in HDMI 2.1 port, customers can directly plug in any modern HDMI display up to 4K 120Hz, 4K 240Hz with DSC, or 8K 60Hz without adapters or dongles.1
  • Up to 81W Host Charging: The dedicated power supply delivers up to 81W through the USB4 host connection. Smart Power Delivery handles allocation between the laptop and connected devices automatically.2
  • Two 10Gb/s USB-C Ports: Two additional USB-C ports for drives, adapters, and accessories at speeds that won’t slow down your workflow.
  • Works With Everything: Compatible with Thunderbolt 5/4/3, USB4, and USB-C Mac, Windows, Linux, and iPad Pro hosts and devices.
  • Silent and Cool by Design: The fanless aluminum housing dissipates heat efficiently for quiet, throttle-free operation.

The OWC USB4 40Gb/s Active Optical Cables, now available in 3-meter and 5-meter lengths, are the fastest, most powerful, and reliable cost-effective solution for long distance Thunderbolt and USB4 connectivity. The cables deliver: 

  • NEW! DisplayPort Alt Mode Series Support: Compatible with both Thunderbolt displays and USB-C displays using DisplayPort Alt Mode. 
  • Placement Flexibility: Solves the longer distance connectivity needs of Thunderbolt 40Gb/s and USB4 devices by enabling optimal placement for a highly organized, convenient, quieter, and productive workspace. Longest reach in the lineup at up to 16 feet (5m model).
  • Uncompromised Speed: Work and play faster with up to 40Gb/s of stable data transfer speed over long distances.
  • Versatile Connections: Connect to externally powered Thunderbolt 40Gb/s and USB4-equipped docks/hubs, displays, eGPUs, PCIe expansion, RAID storage, and more.
  • Power: Lab-certified for safe power delivery from Thunderbolt and USB-C devices that provide power delivery to a host machine.
  • Diverse Displays Compatibility: Supports high-resolution Thunderbolt displays up to 8K, including Apple Pro Display XDR, Apple Studio Display, LG Ultrafine, and other Thunderbolt-based displays. DisplayPort Alt Mode Series cables also support USB-C displays using DisplayPort Alt Mode. 
  • If It’s Lit, You’re Legit: Features LED indicators on both ends that confirm your connection status at a glance.
  • Premium Reliability: Braided nylon exterior over advanced internal fiber optical cable for highly durable and consistent signal reliability; immune to EMI/RFI interference.

The OWC USB4 Hub will be generally available (GA) at the end of October and priced at $129.99. To learn more and pre-order, please visit: https://www.owc.com/solutions/usb4-hub

The OWC USB4 40Gb/s Active Optical Cables will be generally available (GA) in mid-October in 3-meter and 5-meter lengths, and priced at $98.99 and $129.99, respectively. To learn more and pre-order, please visit: https://www.owc.com/solutions/usb4-cables

The industry will have the opportunity to see the new OWC USB4 Hub and USB4 40Gb/s Active Optical Cables in 3-meter and 5-meter lengths during the International Broadcasting ConventionIBC 2026, taking place September 11-14, at RAI Amsterdam, in Hall 7, OWC Booth 7.A60.

82% of Canada’s top AI companies won’t say how long they keep your data says Cybernews

Posted in Commentary with tags on September 9, 2026 by itnerd

New research from Cybernews’ 2026 AI Trustworthiness Ranking reveals a transparency gap among Canada’s leading AI companies: 82% won’t clearly disclose how long they retain user data, and 59% don’t say whether that data is used to train their AI models.

Cybernews has published its ranking, evaluating 500 AI companies across 36 countries on security, data privacy, transparency, and public perception. As part of the project, the team rated 17 leading Canadian AI companies.

Key findings:

  • According to the Cybernews AI Trustworthiness Ranking, Canadian AI companies scored an average of 64 out of 100.
  • 82% of leading Canadian AI companies do not clearly disclose how long they retain user data.
  • 59% of top Canadian AI companies do not clearly disclose whether they use user data to train AI models.
  • Transparency was Canada’s strongest area, with an average score of 92, while security was the weakest at 28.
  • Vidyard ranked first in trustworthiness, followed by Ideogram, Spellbook, LANDR, and Thomson Reuters.

You can explore the full AI Trustworthiness Ranking and individual company scores here: AI Trustworthiness Ranking 2026

Silent Push 6.1 Platform Detects Attacker Infrastructure Earlier for Preemptive Action  

Posted in Commentary with tags on September 9, 2026 by itnerd

Silent Push today announced enhancements to its preemptive cyber defense platform with Silent Push 6.1. The latest version features a complete rebuild of its Brand and Infrastructure Impersonation capabilities, now fully automated so the platform continuously hunts for imposters and keeps customers informed of what it finds on their behalf, and enhanced extensibility to enable analysts to seamlessly integrate into security telemetry and AI tools for faster pivots, and controlled intelligence delivery.

Brand and infrastructure impersonation is now a formal intelligence requirement, not just a marketing concern. Companies are being forced to know what malicious domains, phishing assets, or impersonation campaigns are being used against their brand, and how they can stop them at scale.

Silent Push 6.1 is built to answer that question before the first phishing email is sent. Set it once, and the platform keeps finding new look-alike domains and reporting them to your team on an ongoing basis.

Silent Push 6.1 centers on protecting what matters to organizations and accelerating everything analysts do next. The platform meets analysts where they already work: SOAR platforms, browsers, AI tools, and threat-intel feeds, further shortening the distance between finding threats and acting on them.

New capabilities include:

  • Next-Gen Brand and Infrastructure Impersonation: One of the most direct threats an organization faces is brand and infrastructure impersonation, and 6.1 rebuilds how Silent Push detects it. Configure your brands and assets once, and the engine continuously finds look-alike domains, scores them by risk, enriches them with registrar and hosting context, clusters them by threat actor, and alerts your team with takedown-ready evidence.
  • Advanced Pivot Control: Displays existing Silent Push data and lets you move into WHOIS or open-directory lookups without losing your place in the investigation. Insight Search now understands domains, IPs, ASNs, subnets, and HTML titles in a single query. Total View adds a PADNS timeline, IP certificates, one-click PDF export, and date filtering for screenshots.Ecosystem Reach: With 6.1, the My Assets feature lets you build a reusable list of the infrastructure you own (domains, IP ranges, ASNs, and TLDs), tag it, and reuse it as a one-click input everywhere in the platform.
  • Integrations:
    • Palo Alto Cortex XSOAR: Silent Push intelligence is available inside XSOAR for automated playbooks and response workflows.
    • Chrome Extension: Investigate domains and indicators directly from the browser, without leaving the page you are on.
    • MCP Server: Exposes Silent Push data to AI assistants and agentic workflows over the Model Context Protocol (MCP).
    • Updated TAXII Server: Now supports bidirectional sharing, enabling two-way threat-intelligence exchange over STIX/TAXII.
  • TLP Amber Reports: Custom Silent Push analyst reports now support TLP: AMBER+STRICT, so exclusive, subscription-based intelligence reaches only the organizations and individuals meant to receive them.
  • Internationalization: The interface is now available in Korean and Spanish alongside English, with navigation and guidance fully localized per user, while the underlying data stays the same. Japanese will be available shortly, with additional languages available on customer request.
  • About Silent Push
  • Silent Push is the preemptive cyber defense company. It is the first and only solution to provide a complete view of emerging threat infrastructure in real time, exposing malicious intent through its Indicators of Future Attack® (IOFA) data, enabling security teams to proactively block hidden threats and avoid loss. The Silent Push standalone platform is also available via API, integrating with various security tools, including SIEM & XDR, SOAR, TIP, and OSINT, providing automated enrichment and actionable intelligence. Customers include some of the world’s largest enterprises within the Fortune 500 as well as government agencies. 

free Community Edition is available.

N-able warns MSSPs, MSPs & orgs: patch critical N-central vulnerability NOW

Posted in Commentary with tags on September 8, 2026 by itnerd

N-able is urging users of on-premises N-central to immediately apply its patch for an unauthenticated remote code execution (RCE) vuln to its N-central endpoint management platform, as it’s currently being actively exploited. The platform is widely used among managed service providers (MSPs and MSSPs), and many internal corporate enterprises are also users.

The vulnerability is tracked as CVE-2026-86218 with a CVSS score of 10/10, and was discovered after N-able patched two other flaws in N-central.

“This critical zero-day vulnerability, CVE-2026-86218, could allow pre-authenticated access to the N-central server if exploited. We communicated this 2026.3 hotfix  earlier today, and we want to use this post as a reminder to upgrade immediately if you haven’t already, so we can help keep you and your customers protected,” the company’s alert reads. “Review your logs for scanning activity. We’ve observed scans originating from the IP range 23.234.64.0/18 attempting to exploit this vulnerability. Check your logs for any connections from this range.”

The alert also notes that N-central hosted environments don’t require the patch as it was deployed server-side.

You can read the alert here: N-central Security Update – Take Action to Apply 2026.3 HF4 – N-able

Waseem Ahmed, Head of Engineering at Secure.com

N-able makes N-central, software that IT teams and managed service providers use to watch over and control large numbers of customer computers from one central console. That reach is exactly why this bug is so dangerous.

A single flaw rated 10 out of 10 lets an attacker run code on the N-central server without any login or password first, so one weak spot can open the door to every client network hanging off that platform. Attackers love this kind of target because it turns one break-in into many.

On-premises teams should apply the 2026.3 HF4 hotfix right now, hunt their logs for scans from the flagged IP range, and look for strange new admin accounts. Trusted management tools deserve the same hard scrutiny you give the front door, because attackers already treat them as the shortest path in.

Suzu Labs CTO Denis Calderone:

The severity really comes down to the unprecedented amount of trust it has over its operating environment. It has so much control that you can basically think of a compromised N-central server as having control of a fleet of trojanized nodes; since you own the server, you automatically control all of its nodes. N-able is commonly deployed as an MSP tool, and oftentimes the end client isn’t even aware that they have N-able running because the MSP often white labels the tool as their own. What really worries me is the organization that doesn’t know they have N-able combined with the MSP that hasn’t patched yet. If you want an example of “history repeating” venture back to 2021 when Kaseya VSA got similarly popped; same results.

And the velocity here has our attention. This is N-central’s fourth emergency hotfix in five weeks and their fifth CVE since August. Huntress confirmed a compromised customer environment on September 4, two days before this patch even dropped. Someone is actively picking this platform apart, and the downstream businesses that are most exposed have no mechanism to even know whether their MSP has kept up with the patches.

If you use on-premises N-central, you need to patch all the things ASAP as it is a safe bet that the bad guys are going to leverage this against you if your on-premises N-central instance is attacked.

Google Threat Intel Findings on Adversarial AI 

Posted in Commentary with tags on September 8, 2026 by itnerd

A new report by Google Threat Intelligence Group (GTIG) took a look at the Q2 standings of adversarial AI, finding that threat actors are using multi-agent AI frameworks to automate credential theft, with one attacker building and deploying a campaign that harvested thousands of credentials in under six hours. 

Scott Miserendino, Chief Technology Officer at DataBee, A Comcast Company:

“GTIG’s findings point to a shift in the threat landscape, the same AI tools that accelerate software development and other business processes are now targets themselves. It is little surprise that threat actors have found success in leveraging AI across the kill chain. The fact that attackers are stealing API credentials to AI models and hijacking cloud environments, however, to run unauthorized AI workloads signals that access to frontier AI may be becoming as valuable as traditional data theft. Threat actors are adapting to the economics of AI not just using the technology.”

Dan Moore, Sr. Director, CIAM Strategy & Identity Standards at FusionAuth

“These multi-agent attacks move faster and hit more systems than most security platforms can detect. The prize now goes beyond ransoming or selling your confidential data – access to your proprietary AI models and compute resources are a direct target too. LLMjacking, the arbitrage of stolen IaaS and premium-model compute, is a booming business, and against the top-tier models it can cost victims over $100,000 a day.

The best defense remains short-lived tokens (and the monitoring to ensure they are not being used by attackers), keeping credentials safe from LLMs by using secrets managers, and strong permission models that enforce least privilege at every layer of the stack.”

I’ve said it before and I will say it again. Your plans to defend yourself have to include AI. If not, it is a matter of when not if you will get pwned.

Cyberattack encrypts German utility’s IT systems serving critical infrastructure

Posted in Commentary with tags on September 8, 2026 by itnerd

cyberattack that began September 1st has encrypted the central IT systems of Stadtwerke Landsberg, a municipal utility in Bavaria that provides electricity, water, wastewater treatment, district heating, fiber connectivity and other local infrastructure.

The utility’s office and communications systems are disrupted, leaving employees with limited access to phone and email, but operational systems responsible for electricity, water and other essential utility services were unaffected and continue to operate normally.

Stadtwerke Landsberg said it can’t yet rule out whether attackers accessed or stole customer data, including names, addresses, phone numbers, email addresses and bank information.

Jeremiah Fowler, Cybersecurity Researcher, Black Hills Information Security:

Stadtwerke Landsberg Cyber Attack: An incident like this serves as a reminder that smaller and regional infrastructure providers face the same threats as national utility providers, but they often don’t have comparable cybersecurity budgets or staffing to face the growing threats. This is also a good example of why it is important to have segmentation between business IT networks and operational technology. The ability to isolate compromised systems can also help prevent a cyberattack from becoming a doomsday scenario.

Attackers may see regional critical infrastructure as low hanging fruit when it comes to being a target and these systems could also serve as testing grounds for larger attacks against bigger targets. Another concern is the potential theft of PII. Targeted phishing attempts are a real concern when individuals can be connected to services. Criminals would know account numbers, payment history, and much more that makes these attempts believable and much more dangerous.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

Stadtwerke Landsberg runs electricity, water, wastewater, heating, fiber, and EV charging for a Bavarian town. When it gets breached, the attacker gets a near-complete household profile, names, bank details, addresses, and phone numbers for services residents can’t switch away from. You can change your grocery store after a breach. You can’t change your municipal water provider.

IT/operational technology (OT) segmentation kept Landsberg’s water and power running. That’s the difference between a data breach and a service outage. The thirty-plus U.S. water systems hit across seven states in July show what happens without it.

This happened the same day Germany blamed Russia for a drone strike at Leipzig/Halle airport and saboteurs hit two power substations. I don’t think the attacks are connected, but the operating environment for municipal utilities has changed. Landsberg follows GSW Kamen in June and Windsbach in July.

Article 34 of the General Data Protection Regulation (GDPR) requires notifying affected individuals only when the risk to them is high. Landsberg issued one six days after the encryption.

Ransomware crews want the data. Nation-state actors want the infrastructure. A municipal utility serving one Bavarian town is expected to defend against both.

Noelle Murata, Chief Operating Officer, Xcape, Inc.

A ransomware event against a municipal utility managing electricity, water, wastewater treatment, district heating, and fiber connectivity highlights the multifaceted risk exposure facing regional infrastructure providers. While Stadtwerke Landsberg successfully isolated its operational technology (OT) environment to keep core public services running, central administrative IT systems were encrypted, leaving staff without routine communication tools and raising immediate data exfiltration concerns. The good news is that essential utility delivery remained online during this incident; the bad news is that when multiservice utilities succumb to compromise, the potential failure modes multiply rapidly across a community. The precise initial entry vector and the extent of customer data theft remain unconfirmed.

This incident arrives as German authorities pivot toward a fundamentally proactive cyber posture. Spurred by domestic political activism from anti-fossil fuel movements and internal extremism, along with heightened external threats following the Russian invasion of Ukraine, Germany recently updated legislative frameworks to permit active cyber defense and offensive countermeasures. This reform transforms national strategy from a traditionally reactive stance to one focused on deepening intelligence around specific threat actors, disrupting attacker infrastructure, and deploying counter-intelligence.

Cybersecurity professionals have long debated the efficacy of active defense. As Germany operationalizes these new spy laws, defenders will closely monitor whether proactive disruption deters threat actors or simply accelerates adversarial tactics against critical infrastructure.

Her Critical Takeaways

  • Operational isolation preserved core municipal services at Stadtwerke Landsberg, but administrative IT encryption created severe communication disruptions and data breach risks.
  • German legislative reforms mark a major strategic shift from reactive defense to proactive cyber countermeasures and intelligence gathering against internal and external actors.
  • Security leaders must continuously validate active directory boundaries and cross-domain access controls to prevent administrative IT compromises from threatening operational networks.

Mark my words, something like this is coming to the USA soon. I say that because The CISA is about to be defunded leaving critical infrastructure undefended. Which is bad for everyone.

September Patch Tuesday Commentary From Fortra

Posted in Commentary with tags on September 8, 2026 by itnerd

By Tyler Reguly, Associate Director, Security R&D, Fortra

I think it is safe to say that, as long as Microsoft is playing catch-up on patching vulnerabilities, numbers have lost all meaning. This is not a Microsoft specific problem… we see the same issue with Oracle and other large vendors that are being proactive. We need to remember that these large CVE counts are a good thing as we’re reducing attack surface before attackers get a chance to find and utilize the vulnerabilities. Eventually, all those long-standing, hard to find vulnerabilities will be fixed and Patch Tuesday will return to its typical cadence. Until that happens, prioritization is key and gift cards for extra coffee for your admins would likely be appreciated.

Even though I think it is temporary and we will return to manageable Patch Tuesday’s, I think it’s important that we acknowledge our current normal. Specifically, have you considered your people and processes during what could easily be called trying times? This is a great time to consider if your processes are designed to handle major changes and potential patching bottlenecks. While the number of patches may not have increased greatly (due to cumulative updates), they have increased as we see more and more one-off patches. How do you handle those one-off patches that may require a manual reinstall of the software or the extraction of a zip file to a specific location to overwrite a vulnerable version? These last few months may have disrupted your normal processes, so this is a great time to step back and really look at them. Are there places for improvement? What about your people. How are they handling the current levels of patches and the tickets that those produce. Are they managing? Are they struggling? Have you even stopped to ask them?

It’s time to put our CISOs and CSOs on notice. How are you helping your teams through these difficult times? Are you eliminating soak tests because some public guidance has suggested ridiculously short patch timeframes? Does that put added stress on your teams because they don’t know what outages they may see as a result? If you’re doing this… STOP! Patches still need to be tested because not all vendors can be trusted and many have broken the trust they had previously gained. Test your patches before you deploy them. Then, think about your deployment. Do you have your teams deploy after hours and on weekends to avoid disruption to the business environment? Do you reward them for that effort? Time to dig into your budget and buy dinner for your teams that are working on Saturday to get patches rolled out before users return to work on Monday.

Right now, if you are in charge of teams managing patches, you are probably struggling with what to do. Support your team, be aware of the difficulties they face, and ask them how things can be improved. If you still prioritize based on CVSS, you are hurting your organization and your employees. If you are constantly flip-flopping as guidance changes, you are putting your organization at risk and jeopardizing employee happiness. You are essentially steering a ship through rough waters, and you need a steady hand to accomplish that. If you keep the ship on course, your team will be able to do the rest.

MikroTik routers have been pwned

Posted in Commentary on September 8, 2026 by itnerd

If you own a MikroTik router, bad news. You router is vulnerable to getting pwned:

Critical MikroTik authentication-bypass and privilege escalation vulnerabilities allow external attackers to seize control of routers via exposed SSH ports, and active exploitation is already underway. The manufacturer chose to issue a vaguely worded security update, even as 122,500+ MikroTik routers sit with SSH exposed.

MikroTik shipped RouterOS fixes on September 3rd, 2026, with release notes that mention only an “important security update.” The company strongly recommends an update, but provides no technical details.

For the first time ever, MikroTik also sent users a push notification through its app to alert them about the update.

“To give time to update your systems, we are not currently publishing detailed information,” the security advisory reads.

Larry Pesce, VP of Services, Finite State (https://www.linkedin.com/in/larrypesce)

“The interesting thing about MikroTik isn’t the CVE chain itself, it’s what it says about where attackers keep choosing to point their effort. This is a very old argument dressed up in new CVEs. Network infrastructure was the original attack surface, back when worms and DNS cache poisoning and route hijacking were the front page news. Then defenders hardened the perimeter, and attackers moved to the endpoint: client-side exploits, macros, phishing. Then EDR got good at watching endpoints, and attackers moved again, first to cloud and identity, then to the explosion of IoT and connected devices that nobody was watching at all.

“Now the pendulum is swinging back toward infrastructure. Edge appliances, VPN gateways, and routers like these MikroTik boxes are attractive again for exactly the reason they were attractive twenty years ago: almost nothing runs an agent on them, almost nobody patches them promptly, and almost nobody actually knows how many of them they have exposed to the internet.

“That last point is the one worth sitting with. Most organizations have spent the last decade building real inventory and telemetry for laptops and servers. Very few have done the same for the network gear sitting between those systems and the internet. A router doesn’t show up in your EDR console. It usually isn’t in the CMDB unless someone remembered to put it there. It gets touched during install and then left alone until something breaks. That is precisely the blind spot this kind of campaign is built to exploit, and it’s also why 120,000 exposed devices is a plausible number rather than a shocking one. Nobody set out to leave that many boxes reachable on purpose. It’s an accumulation of the same basic inventory gap, repeated at scale.

“There’s also a targeting-philosophy shift worth naming. Compromising a router at scale isn’t usually about that one router. It’s about building a broad, disposable base, proxy points, relay infrastructure, a wide net of footholds, rather than a single surgical intrusion into one high-value target. That’s a different economic model than the supply-chain-style precision compromise we talk about more often, and it changes what ‘defense’ needs to look like.

“You’re not trying to stop one determined actor from reaching one target. You’re trying to avoid being one anonymous node in somebody’s infrastructure, which is a numbers game, and numbers games get won or lost on unglamorous things like patch cadence and knowing what you actually have exposed.

“None of this is new. It’s the same swing the industry has made every few years: infrastructure, then endpoint, then cloud, then device, and back to infrastructure again, each time landing wherever defenders most recently stopped paying attention.

“The lesson isn’t really about MikroTik. It’s that ‘know your inventory’ never stopped being step one, and the network layer is overdue for the same rigor we finally applied to endpoints.”

If you have one of these routers, update now. If you can’t update it, toss it and get a new one. Because you can bet that the bad guys are trying to pwn everything that they can.