Skip to content

Sam's News — security — 2026-09-06

Security

7.5 MikroTik Routers Compromised Via Unauthenticated Internet-Exposed SSH Access

Attackers are exploiting unauthenticated SSH access on internet-exposed MikroTik routers to gain full administrative control. CERT Polska warned of the vulnerability chain on September 5, 2026, with active attacks documented since at least September 2. MikroTik released patches for affected RouterOS versions.

  • Vulnerability termed 'MikroTrick' involves two unidentified flaws bypassing SSH authentication
  • Affected RouterOS: 6.0.0–6.49.20, 7.0.0–7.23.3, 7.24.0–7.24.1
  • Patches released: 6.49.21, 7.23.5, 7.24.2
  • Attacks documented since at least September 2, 2026
  • Post-compromise indicators: Flagged status warnings, unknown accounts, ssh:-2@ pattern in logs

Sources: The Hacker News AI Web Searched

7.5 Trezor ShipMonk data breach exposes 67,000 U.S. customer records via Metabase zero-day

A data breach at Trezor ShipMonk exposed 67,000 U.S. customer records through exploitation of a Metabase zero-day vulnerability (CVE-2026-72898).

Sources: Rescana RSS

7 REVSTEALER Malware Modules Disable Windows Defenses to Enable Cryptocurrency Mining

Elastic Security Labs identified four previously unknown programs linked to REVSTEALER malware that disable Windows defenses and deploy cryptocurrency mining. The tools—ProManager, WinUpdate, SoftManager, and LockAppHost—persist after REVSTEALER's core stealer removes itself, with LockAppHost disabling Windows Update services and Defender protections to run a hidden miner.

  • Four new REVSTEALER-linked programs: ProManager, WinUpdate, SoftManager, LockAppHost
  • REVSTEALER: Windows information stealer sold commercially since February 2026
  • LockAppHost disables 5 Windows Update services, 11 scheduled update tasks, 2 malware removal tasks
  • ProManager steals wallet files and browser extensions, overlays attacker content
  • WinUpdate monitors clipboard, replaces cryptocurrency addresses with attacker's
  • Findings published September 2, 2026

Sources: The Hacker News AI Web Searched

7 Large-Scale Phishing Campaign Uses Invisible Unicode and ActiveCampaign to Evade Filters

Attackers are running a widespread phishing campaign using invisible Unicode characters and the ActiveCampaign marketing platform to evade email security filters.

Sources: Rescana RSS, BleepingComputer RSS