Finite State's Larry Pesce: Attackers Are Coming Back for Infrastructure Everyone Forgot to Watch

Finite State's Larry Pesce: Attackers Are Coming Back for Infrastructure Everyone Forgot to Watch

BackerLeader 44 256 449
calendar_today agoschedule4 min read

Over the past week, attackers have been hijacking MikroTik routers at scale, exploiting a chain of RouterOS vulnerabilities CERT Polska calls "MikroTrick." Two flaws, an SSH authentication bypass and a privilege escalation triggered by a specially crafted username, combine to give an unauthenticated attacker full administrative control of any exposed device. As of a September 5 scan, the Shadowserver Foundation counted more than 122,500 MikroTik devices with SSH reachable from the open internet, concentrated in Brazil, the U.S., Indonesia, the Czech Republic, and Ukraine. Exploitation began September 2, a day before MikroTik shipped patches and three days before CERT Polska published the technical detail defenders needed to detect it.

There's a detail in how these flaws were found that's easy to miss under the exploitation headlines: CERT Polska's team used OpenAI's GPT-5.5-cyber and GPT-5.6-sol models, through the vendor's Government and Trust Agency Collaboration program, to automate version comparison, RFC analysis, and binary review, with researchers independently verifying every finding before disclosure. That's AI accelerating the defensive side for once, not just the offensive one, though the exploitation timeline that followed shows how little breathing room that head start actually buys.

The pendulum, not the CVE, is the real story

Larry Pesce, VP of Services at Finite State, argues the specific vulnerabilities matter less than the pattern they fit into. "This is a very old argument dressed up in new CVEs," he said. "Network infrastructure was the original attack surface, back when worms and DNS cache poisoning and route hijacking were the front page news."

His read on the last two decades of attacker behavior is a pendulum, not a straight line. Defenders hardened the network perimeter, so attackers moved to the endpoint: client-side exploits, macros, phishing. EDR got good at watching endpoints, so attackers moved to cloud and identity, then to the sprawl of IoT and connected devices nobody was monitoring at all. Now, Pesce argues, the swing is back toward infrastructure. "Edge appliances, VPN gateways, and routers like these MikroTik boxes are attractive again for exactly the reason they were attractive twenty years ago: almost nothing runs an agent on them, almost nobody patches them promptly, and almost nobody actually knows how many of them they have exposed to the internet."

The inventory gap nobody closed

Pesce's sharpest point is about where organizational attention actually went over the past ten years. "Most organizations have spent the last decade building real inventory and telemetry for laptops and servers. Very few have done the same for the network gear sitting between those systems and the internet," he said. A router doesn't show up in an EDR console. It usually isn't in the CMDB unless someone remembered to add it. It gets touched during install and then left alone until something breaks.

That gap is exactly what a campaign like this is built to exploit, and it's why Pesce doesn't find 122,500 exposed devices a shocking number so much as a predictable one. "Nobody set out to leave that many boxes reachable on purpose. It's an accumulation of the same basic inventory gap, repeated at scale."

A numbers game, not a single-target intrusion

Pesce also draws a distinction worth sitting with: compromising a router at scale usually isn't about that one router. "It's about building a broad, disposable base, proxy points, relay infrastructure, a wide net of footholds, rather than a single surgical intrusion into one high-value target," he said. That's a different economic model than the supply-chain-style precision compromise that tends to dominate security headlines, and it changes what defense needs to look like. "You're not trying to stop one determined actor from reaching one target. You're trying to avoid being one anonymous node in somebody's infrastructure, which is a numbers game, and numbers games get won or lost on unglamorous things like patch cadence and knowing what you actually have exposed."

What MikroTik is asking affected users to do

Beyond patching, MikroTik's advisory asks administrators to actually check whether they've already been compromised. Updated RouterOS versions can flag a device's status after checking logs; a device marked "Flagged" should be treated as compromised outright, not just patched and left alone. Simply updating isn't sufficient on its own; the compromise can predate the fix. CERT.LV, for its part, said it had already confirmed a dozen compromised devices in Latvia out of several thousand exposed there, notified critical infrastructure operators, and continues tracking the fallout.

Not really a MikroTik story

Pesce's closing point is the one worth carrying into any infrastructure review this prompts. "None of this is new. It's the same swing the industry has made every few years: infrastructure, then endpoint, then cloud, then device, and back to infrastructure again, each time landing wherever defenders most recently stopped paying attention," he said. "The lesson isn't really about MikroTik. It's that 'know your inventory' never stopped being step one, and the network layer is overdue for the same rigor we finally applied to endpoints."

For developers and architects, the practical takeaway isn't a MikroTik-specific patch checklist. It's a question worth asking about every edge appliance, VPN gateway, and router sitting on the network: does it show up anywhere your team actually looks, or has it just been sitting there since install, waiting for its turn?

🔥 Join developers growing publicly
Share your knowledge, build in public, and grow your developer presence with a global community.

More Posts

Your Backup Data Knows More Than You Think. HYCU aiR Is Finally Asking It the Right Questions.

Tom Smithverified - May 14

Attackers Know Your Human Patterns Better Than You Do

Muhammad Ali Khan - Dec 16, 2025

Are You Ready for the 2026 OT Cyber Compliance Wave?

Muhammad Ali Khan - Dec 27, 2025

PQC Migration: What an Enterprise Consultant and a Network Vendor Are Actually Seeing

Tom Smithverified - Jul 28

Everyone says DeepSeek is cheaper, but I got tired of guessing the exact math. So I built a calculat

abarth23 - Apr 27
chevron_left
17.6k Points749 Badges
233Posts
134Comments
96Connections
LLM Training & Evaluation Specialist with hands-on experience building major AI models. As one of th... Show more

Related Jobs

View all jobs →

Commenters (This Week)

2 comments
1 comment
1 comment

Contribute meaningful comments to climb the leaderboard and earn badges!