In today’s cybersecurity news…
MikroTik routers hijacked through internet-exposed SSH
Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication. This is according to Poland’s
CERT Polska
, which identified and coordinated the disclosure of six vulnerabilities in MikroTik RouterOS and published a warning this past Saturday.
MikroTik
has released a security update lists which will prevent the observed attacks.
(The Hacker News and CERT Polska)
Russian data centers face new security requirements
The operators of Russian data centers are looking to beef up their physical defenses as part of a Kremlin-led tightening of security requirements for critical infrastructure as a result of continued Ukrainian drone attacks. The decree also allows the Russian government to “temporarily take control of critical infrastructure if operators fail to adequately protect their facilities, including from drone attacks.” The decree covers a broad range of critical infrastructure sectors, including data centers used by government agencies, banks and major service providers.
UK account-hack losses surge thanks to new reporting system
“Reported losses tied to hacked email, social media and other online accounts in Britain rose 417% over the last financial year,” says a report published on Friday by the
City of London Police
force. Victims reported losing a total of £6.3 million ($8.5 million) to account hacks in the year ending March 31. The number of people reporting a financial loss rose from 226 to 2,325, an increase of 929%. Police state, however, that the increase “reflects changes in how incidents are reported rather than a sudden fivefold increase in attacks.” They add that these numbers likely “represent a small fraction of total cybercrime losses because they rely on voluntary self-reporting.”
Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
According to researchers at cloud security platform
Netskope
, “a massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC).” Most of these hacked websites were built on WordPress and PrestaShop. In a technique called EtherHiding, each site was “injected with a script that gets the next-stage payload from a smart contract on the BSC Testnet endpoint.” This enables threat actors to “store malicious code or configuration data in blockchain smart contracts, providing a resilient infrastructure that is difficult to take down.”
Big thanks to our sponsor,
ThreatLocker
Another zero-day exploit for SonicWall
Researchers from
Rapid7
are warning that these new zero-days, a maximum severity pre-authentication server-side request forgery vulnerability and a high-severity OS command injection vulnerability, “can be chained together to achieve unauthenticated remote-code execution.” This is the latest in a series of zero-day vulnerabilities in SonicWall SMA 1000 appliances. Patches for the CVE numbered vulnerabilities (CVE-2026-83548 and CVE-2026-83549) have been released, but both vulnerabilities have already been exploited in the wild.
Cybersecurity and Infrastructure Security Agency
added the defects to its known exploited vulnerabilities (KEV) catalog Wednesday.
ASCII smuggling used for old-school phishing
Although much news has been made recently of hackers using ASCII characters to hide malicious prompts inside AI models,
Microsoft
is reporting on a massive phishing campaign that uses invisible Unicode tag characters to “hide content inside email copy but rather than using for prompt injection, Unicode tag spaced between letters help to evade keyword matching and content filters. This is done by inserting one in the middle of an often flagged word such as “funding,” so that it appears as “fun⟨U+E0020⟩ding.” Microsoft first detected this campaign in early February, with millions of emails being sent daily from 150 finance-themed sender domains.
Young job seekers face thefts through employment scams
Job interview scams are nothing new, but
LinkedIn
is reporting on how some younger job seekers are losing their savings to crypto-draining malware embedded in downloadable job interview documents. Named by LinkedIn as The Gen Z “Scam Gap” the campaign is mostly impacting younger professionals with nearly one third (32%) of those interviewed admitting to ignoring potential red flags due to a competitive job market. Speaking to the BBC, the authors of the LinkedIn report pointed out “many young people feel they can’t afford to be skeptical… because they feel opportunities are so scarce.”
Microsoft says some users can’t open the Teams desktop client
Microsoft
says it is “working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems.” This known issue has a tracking number and was acknowledged on Thursday. Microsoft advises affected customers to work around it by using the web or mobile platforms. Its technicians are analyzing service logs and telemetry data “and has also reached out to some affected users to identify the root cause and determine mitigation options.”
Subscribe to Cybersecurity Headlines podcast
Spotify, Apple Podcasts, YouTube, RSS link, Amazon Music, add as an Alexa Skill, or search “Cybersecurity Headlines” on your favorite podcast app.
Click Here For The Original Source.
