If you have any Ubiquiti devices that aren’t running at the most current patch level, if those devices are reachable from the Internet, you should patch them IMMEDIATELY.
According to this thread on Ubiquiti’s forum site, there is a worm exploiting unpatched AirOS and other devices. I can confirm that over the past 24 hours, I’ve seen several Ubiquiti devices hitting my SSH honeypots (I’ve seen at least one EdgeOS device, but I can’t yet confirm that it’s part of the same issue…)
Owner, Principal Consultant
Bad Wolf Security, LLC
Senior Technical Engineer
May 15, 2016