MikroTik released a patch late last week for an SSH authentication bypass that is already being exploited, SANS ISC reports. The diary's guidance is blunt: at this point, assume compromise.

Attackers have been adding new accounts to affected devices so they keep access even after the patch is installed, which means patching alone may not evict an intruder.

For small teams running MikroTik gear, the protective step is to apply the patch and then review affected devices for accounts that should not be there.