top of page
Untitled design.png

Weekly INK

Each week we compile an advisory on the latest threats, trends and newsworthy topics from the cyber security industry affecting small and medium enterprises. Join our subscribers below and help us prevent cybersecurity breaches.

watermark4.png

Issue #216 - September 14, 2026

5 days ago
2 min read

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

Source: SecurityWeek

CISA will retire its weekly vulnerability bulletin on September 28 as it shifts federal vulnerability management toward real-world risk. The agency says BOD 26-04 emphasizes active exploitation, exposure, and the Known Exploited Vulnerabilities catalog, helping defenders prioritize urgent fixes instead of sorting thousands of entries primarily by severity.




Cyber Op Targets South Korean Media & Automotive Sectors

Source: Dark Reading

Rapid7 linked a stealthy campaign against South Korean media and automotive organizations to North Korean operators with medium confidence. Attackers embedded a previously undocumented Linux toolkit called TED into HAProxy load balancers, enabling credential theft, traffic manipulation, and long-term espionage while minimizing the processes, connections, and logs defenders normally inspect.




Most Fraudulent Hires Receive Credentials Before Detection

Source: Infosecurity Magazine

A HYPR survey of 500 US HR executives found that fraudulent candidates often clear screening and receive corporate credentials before detection. Fraudulent hires reportedly retain unmonitored network access for an average of 5.73 days, underscoring the need to coordinate identity verification, hiring controls, IT provisioning, and security monitoring.




BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

Source: The Hacker News

The Internet Systems Consortium released BIND 9.20.29 and 9.21.26 to fix 14 vulnerabilities, seven rated high severity. One flaw can let an unauthenticated sender crash a DNS-over-HTTPS server with a crafted request. ISC reported no known active exploitation, but public reproduction tests clarify trigger conditions and raise the urgency of patching.




US takes down NightmareStresser DDoS-for-hire platform

Source: BleepingComputer

The FBI seized two domains used by NightmareStresser, a long-running DDoS-for-hire service that allegedly supported hundreds of thousands of attacks since 2022. The action formed part of the international Operation PowerOFF effort targeting booter infrastructure, which rents botnets of compromised routers and IoT devices to customers.




 
 

Help us Prevent Breaches.

We will never share or sell your information. Unsubscribe at any time.

Email: *

Received.

bottom of page