Attackers have been exploiting internet-exposed SSH services on MikroTik routers since at least September 2, gaining full administrative control without authentication through a two-vulnerability chain dubbed "MikroTrick" by CERT Polska. Affected devices run RouterOS versions across the 6.x, 7.x, and development channels, with fixes available in releases 6.49.21, 7.23.4/7.23.5, 7.24.2, and 7.25beta3. Users are urged to install updates immediately, check for signs of compromise such as unknown accounts or suspicious logs, and temporarily restrict access to exposed services until patching is complete.