Issue #216 - September 14, 2026
CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot
Source: SecurityWeek
CISA will retire its weekly vulnerability bulletin on September 28 as it shifts federal vulnerability management toward real-world risk. The agency says BOD 26-04 emphasizes active exploitation, exposure, and the Known Exploited Vulnerabilities catalog, helping defenders prioritize urgent fixes instead of sorting thousands of entries primarily by severity.
Cyber Op Targets South Korean Media & Automotive Sectors
Source: Dark Reading
Rapid7 linked a stealthy campaign against South Korean media and automotive organizations to North Korean operators with medium confidence. Attackers embedded a previously undocumented Linux toolkit called TED into HAProxy load balancers, enabling credential theft, traffic manipulation, and long-term espionage while minimizing the processes, connections, and logs defenders normally inspect.
Most Fraudulent Hires Receive Credentials Before Detection
Source: Infosecurity Magazine
A HYPR survey of 500 US HR executives found that fraudulent candidates often clear screening and receive corporate credentials before detection. Fraudulent hires reportedly retain unmonitored network access for an average of 5.73 days, underscoring the need to coordinate identity verification, hiring controls, IT provisioning, and security monitoring.
BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
Source: The Hacker News
The Internet Systems Consortium released BIND 9.20.29 and 9.21.26 to fix 14 vulnerabilities, seven rated high severity. One flaw can let an unauthenticated sender crash a DNS-over-HTTPS server with a crafted request. ISC reported no known active exploitation, but public reproduction tests clarify trigger conditions and raise the urgency of patching.
US takes down NightmareStresser DDoS-for-hire platform
Source: BleepingComputer
The FBI seized two domains used by NightmareStresser, a long-running DDoS-for-hire service that allegedly supported hundreds of thousands of attacks since 2022. The action formed part of the international Operation PowerOFF effort targeting booter infrastructure, which rents botnets of compromised routers and IoT devices to customers.



