
MikroTik routers hijacked, Russian data center threats, UK cybercrime losses surge
About this episode
MikroTik routers hijacked through internet-exposed SSH
Russian data centers face new security requirements
UK account-hack losses surge thanks to new reporting system
Get the show notes here: https://cisoseries.com/cybersecurity-news-mikrotik-routers-hijacked-russian-data-center-threats-uk-cybercrime-losses-surge/
Huge thanks to our episode sponsor, ThreatLocker
AI is helping attackers research targets, create malicious code, and adapt faster. But the fundamentals have not changed. Code still needs to execute, applications still need access, and attackers still need privileges. Today's tip: control those actions instead of trying to predict every threat. Learn more from ThreatLocker at threatlocker.com/ciso.
Get every episode summarized
Each time Cybersecurity Headlines publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
51 searchable segments. Every word is indexed and playable.
Full transcript
Cybersecurity Headlines — MikroTik routers hijacked, Russian data center threats, UK cybercrime losses surge. Machine-transcribed; use the interactive transcript above to jump the player to any line.
From the CISO series, it's Cybersecurity Headlines. These are the Cybersecurity Headlines for Monday, September 7th, 2026. I'm Steve Prentice. Microtick routers hijacked through Internet exposed SSH. Attackers are exploiting Microtick routers with their Secure Shell SSH Remote Access Service, which is reachable from the Internet, and they are using this to gain full administrative control without authentication. This is according to Poland's CERT Polska, which identified and coordinated the disclosure of six vulnerabilities in Microtick router OS, and published a warning this past Saturday. Microtick has released a security update to prevent further attacks. Russian data centers face new security requirements. The operators of Russian data centers are looking to beef up their physical defenses as part of a Kremlin-led tightening of security requirements for critical infrastructure as a result of continued Ukrainian drone attacks.
The decree also allows the Russian government to, quote, temporarily take control of critical infrastructure if operators fail to adequately protect their facilities, including from drone attacks. The decree covers a broad range of critical infrastructure sectors, including data centers used by government agencies as well as banks and major service providers. UK Account Hack Losses Surge thanks to new reporting system. Reported losses tied to hacked email, social media, and other online accounts in Britain rose 417% over the last financial year, says a report published on Friday by the City of London Police Force. Victims reported losing a total of 6.3 million pounds equivalent to 8.5 million dollars to account hacks in the year ending March 31. The number of people reporting a financial loss rose from 226 to 2325, an increase of 929%.
Police say however that the increase, quote, reflects changes in how incidents are reported rather than a sudden five-fold increase in attacks, end quote. They add that these numbers, however, likely represent a small fraction of total cybercrime losses because these rely on voluntary self-reporting. Over 5,400 hacked sites serve click-fix payloads stored on the blockchain. According to researchers at Cloud Security Platform NetScope, that is NETSK OPE, quote a massive cybercriminal operation is leveraging thousands of compromised small business websites to deliver click-fix payloads stored in smart contracts on the BNB smart chain. Most of these hacked websites were built on WordPress and Presta Shop. In a technique called Ether Hiding, each site was, quote, injected with a script that gets the next stage payload from a smart contract on the testnet endpoint, end quote.
This enables threat actors to, quote, store malicious code or configuration data in blockchain smart contracts, providing a resilient infrastructure that is difficult to take down. End quote. Huge thanks to our sponsor, Thread Locker. AI is helping attackers research targets, create malicious code and adapt faster. But the fundamentals have not changed. Code still needs to execute. Applications still need access and attackers still need privileges. Today's tip? Control those actions instead of trying to predict every threat. Learn more from Thread Locker at Threadlocker.com slash CISO. Another zero-day exploit for Sonic Wall. Researchers from Rapid Seven are warning that these new zero days, a maximum severity pre-authentication server side request for jury vulnerability,
and a high severity OS command injection vulnerability can be, quote, chained together to achieve unauthenticated remote code execution end quote. This is the latest in a series of zero-day vulnerabilities in Sonic Wall SMA 1000 appliances. Patches for these CVE numbered vulnerabilities have been released, but both have already been exploited in the wild. CISA added the defects to its KEV catalog last Wednesday. ASCII smuggling used for old school fishing. Although much news has been made recently of hackers using techniques like ASCII characters to hide malicious prompts inside AI models, Microsoft is reporting on a massive fishing campaign that uses invisible unicode tag characters to hide content inside email copy, but rather than using it for prompt injection, unicode tags spaced between letters help to evade keyword matching in content filters.
This is done by simply inserting one in the middle of an often flagged word such as funding, so that it appears to the computers at least as FUN, an ASCII character, and then DING. Microsoft first detected this campaign in early February with millions of emails being sent daily from about 150 finance themed sender domains. Young job seekers face thefts through employment scams. Job interview scams are nothing new of course, but LinkedIn is reporting on how some younger job seekers are losing their savings to crypto draining malware embedded in downloadable job interview documents. Named by LinkedIn as the Gen Z scam gap, the campaign is mostly impacting younger professionals with nearly one third 32% of those interviewed, admitting to ignoring potential red flags due to a competitive job market. Speaking to the BBC, the authors of the LinkedIn report pointed out quote, many young people feel they can't afford to be skeptical because they feel opportunities are so scarce.
End quote. Microsoft says some users can't open the teams desktop client right now. Microsoft says it is quote working to resolve a known issue that causes delays or blocks some users from opening the Microsoft teams desktop client on Windows systems end quote. This issue has a tracking number and was acknowledged on Thursday. Microsoft advises affected customers to work around it by using the web or mobile platforms. Its technicians are analyzing service logs and telemetry data and have also reached out to some affected users to identify the root cause and determine mitigation options. If you have some thoughts in the news from today or about this show in general, please be sure to reach out to us at Feedback at CISOSeries.com. We would love to hear from you. I'm Steve Prentice reporting for the CISOSeries. Cybersecurity headlines are available every weekday. Head to CISOSeries.com for the full stories behind the headlines.
More episodes
More from Cybersecurity Headlines

The Department of Know: Astra launches, CISA cuts programs, McKesson breached
Cybersecurity Headlines

Court records breach, Breeze Comet hits Brazil, Aesto records breach
Cybersecurity Headlines

153M licenses for sale, Anthropic reverses course, Astra enters the red zone
Cybersecurity Headlines

Fable 5.1 released, USPS "untested" IT, Exchange hijack vulnerability
Cybersecurity Headlines
