<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Detection on Tolmo</title><link>https://tolmo.com/tags/detection/</link><description>Recent content in Detection on Tolmo</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 06 Sep 2026 01:00:00 -0700</lastBuildDate><atom:link href="https://tolmo.com/tags/detection/index.xml" rel="self" type="application/rss+xml"/><item><title>Pre-auth RCE on MikroTik: exploited before the patch, rebuilt in three hours</title><link>https://tolmo.com/blog/mikrotrick-agentic-detection/</link><pubDate>Sun, 06 Sep 2026 01:00:00 -0700</pubDate><guid>https://tolmo.com/blog/mikrotrick-agentic-detection/</guid><description>&lt;h2 id="in-short"&gt;In short&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;MikroTrick chains two RouterOS bugs into a full, unauthenticated takeover of
any MikroTik device with SSH reachable. Exploitation ran from September 2,
&lt;strong&gt;one day before the patches and three days before the advisory&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;We reproduced the entire chain end to end from only the public advisory and
the patch diff, in a single uninterrupted run: &lt;strong&gt;approximately three hours and
roughly 110,000 tokens&lt;/strong&gt; (the token count covers the main session; the
subagent that reverse-engineered the patched binaries in the background ran
on top of that), verified
against both vulnerable releases. Four frontier models given the same inputs
failed.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;These devices no longer sit only at the edge.&lt;/strong&gt; They wire up local AI
clusters (the DGX Spark, TP&amp;gt;2 crowd), so one compromise exposes model
weights, datasets, and all east-west traffic.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Defense still investigates at ticket speed while offense iterates at agent
speed&lt;/strong&gt;, and CERT Polska cannot rule out additional undisclosed bugs. The
detection section and IoC table below are the checks to run now.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;On September 5, &lt;a href="https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/"&gt;CERT Polska
disclosed&lt;/a&gt;
six vulnerabilities in MikroTik RouterOS.
Two of them chain into &lt;strong&gt;MikroTrick&lt;/strong&gt;: a full, unauthenticated takeover of any
router with SSH reachable. Attackers had been using it since at least
September 2, a day before MikroTik shipped fixes and pushed a
notification to every phone running its app, begging people to update.&lt;/p&gt;</description></item></channel></rss>