Their extra admin survived your firmware update.

SANS handlers spent Sunday on a point most cybersecurity programs still treat as optional cleanup: if a management service on the public internet was bypassable, you should assume the box is occupied. Attackers hitting a recently patched MikroTik SSH issue have been creating local accounts so access survives the upgrade. The code changes. The user table does not.

Extra accounts survive the reboot

You already know the rhythm. Advisory drops. Change ticket opens. Firmware lands. The dashboard shows a current version and someone marks the risk closed. That workflow is built for bugs. Occupied devices need a different close condition.

Vendors keep local users across upgrades on purpose. You would riot if a firmware bump deleted the only admin and bricked a remote site. Attackers read the same release notes. They add a quiet account with a boring name, then wait for you to feel safe because the advisory flipped to patched.

On a router, a firewall, or any appliance with a local AAA store, persistence looks like a user you did not create, an SSH key you did not enroll, or a GUI account that almost matches your naming standard. After an authentication bypass, password quality and brute-force lockouts never got a vote. The session succeeded because the check did not run.

Threat detection that ranks failed passwords will stay quiet. Successful mystery logins on the management VRF look like routine work if you never baselined who belongs there. Edge threat-protection licenses inspect traffic. They do not inventory humans. The durable foothold is an identity record sitting in NVRAM, waiting for the reboot you called a recovery.

Treat every internet-reachable admin plane as in-scope for incident response. SSH, HTTPS, vendor GUI: if an untrusted network could reach it during the window, the device is a crime scene that happens to still route packets. You do not need the CVE string to start. You need last month’s local user list and tonight’s.

Diff them.

Cybersecurity programs close the wrong ticket

Closing on “version current” trains people to stop at the control that is easiest to screenshot. Security hardening on appliances is mostly configuration and identity. Firmware is the part vendors can hash. Local users are the part you own, and they are the part this campaign expects you to skip.

Defense in depth on the slide deck includes the management plane. In the change calendar it often means a WAN filter exists and nothing else. A management ACL is useful. It does not tell you whether an extra admin was added from a session that already walked through SSH. If you only prove the new image, you prove the attacker now runs on patched code with a durable login.

Your cyber security metrics probably already count missing patches as overdue risk. Count unexplained appliance accounts the same way. A local user with no ticket is a finding. A local user created during the exposure window is an incident. Put those two sentences in the runbook before the next advisory.

The SOC may never get a page. There is no malware hash and no beacon your laptop agents will see. Appliance compromise often looks like silence plus a name you will only notice if you ask.

That delay is the whole design.

Inventory users like you inventory firmware

Do the ugly work on every appliance that had management exposure during the window, including boxes you “only use for routing.” Immediate actions first. Then make the check boring enough that it actually happens.

  • Pull the live local user list, group membership, and SSH authorized keys from each device. Export it off-box. Use the same command or API you would use in an audit, not a screenshot of the GUI.
  • Compare against the last known-good backup taken before the exposure window. Every add, rename, or privilege bump needs an owner. No owner means disable and rotate.
  • Turn off WAN-side administration until you finish. Management belongs on a dedicated network, jump host, or out-of-band path. If the internet can still see SSH, you are still taking votes from strangers.
  • Snapshot the dirty config for forensics, then rotate every local secret, cert, and API token, plus upstream RADIUS, LDAP, cloud, and VPN credentials the box could have seen. Rebuild from known-good identity data. Restoring a backup that already contains the extra admin is how you launder persistence.

Ongoing work should be dull. Snapshot appliance users on a schedule and alert on deltas the same way you alert on new firewall rules. Fold those identities into access reviews. Put unexplained local admins in your incident response severity matrix next to domain admins. For a lot of plants, that router is how you reach everything else.

Stop treating vendor GUI accounts as facilities leftovers. They are privileged identities. Give them unique names, hardware-backed credentials where the platform allows it, and a break-glass user stored offline. If your only admin is named admin, you will never see the second one land.

None of this requires a new product. It requires a close condition that matches the failure: known-good people on the box, management plane unreachable from the internet, and a ticket that cannot close on firmware alone.

Patch anyway.

Then prove they left.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.