Weekly review

ThreatNoir Afternoon Brief — September 17

2026-09-17Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — September 17, 2026

The cybersecurity landscape continues to shift rapidly as critical vulnerabilities emerge and law enforcement takes action against established threats. Today's developments span authentication bypass risks, international espionage campaigns, and infrastructure disruptions that demand immediate attention from security teams worldwide.

Cisco Warns of Maximum-Severity ISE Zero-Day Exploited in Attacks

Cisco has released security updates to address a maximum-severity vulnerability in Identity Services Engine that attackers are actively exploiting in the wild. The vulnerability allows for authentication bypass, presenting an immediate risk to organizations relying on Cisco ISE for network access control and identity management. Source: Cisco warns of max severity ISE zero-day exploited in attacks

Multiple CVEs have been assigned to related issues, including CVE-2025-20337, CVE-2026-20176, CVE-2026-20211, CVE-2026-20284, CVE-2026-20307, CVE-2026-76423, and CVE-2026-76460. Organizations running affected versions should prioritize patching to prevent unauthorized access to critical network infrastructure.

US Takes Down NightmareStresser DDoS-for-Hire Platform

The U.S. Federal Bureau of Investigation has seized the domains used by NightmareStresser, one of the world's longest-running distributed denial-of-service platforms. The takedown represents a significant enforcement action against a service that has facilitated thousands of DDoS attacks against targets globally. Source: US takes down NightmareStresser DDoS-for-hire platform

The seized domains nightmare-stresser.com and nightmarestresser.org will no longer be available to threat actors seeking to launch attacks. This action demonstrates continued law enforcement commitment to disrupting criminal infrastructure that enables cyberattacks.

Chinese Hackers Use SparroWocky Malware in Government Espionage Attacks

The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks against government organizations in Latin America. The malware represents an evolution in the group's toolkit and indicates sustained targeting of sensitive government entities in the region. Source: Chinese hackers use SparroWocky malware in govt espionage attacks

Security researchers have identified multiple infrastructure indicators associated with the campaign, including IP addresses across the 185.199.108.0 through 185.199.111.0 ranges used for command and control operations. The deployment of SparroWocky alongside the previously known SparrowDoor malware suggests a coordinated espionage effort targeting high-value government networks.

Microsoft Shares Workaround for Windows Domain Login Issues

Microsoft has provided a temporary fix for a known issue affecting Windows 11 users who cannot log in with valid domain credentials after installing September 2026 security updates. The problem stems from enforcement mode functionality in the latest patches and impacts organizations managing large Windows deployments. Source: Microsoft shares workaround for Windows domain login issues

Organizations experiencing authentication failures should implement Microsoft's recommended workaround while awaiting a permanent resolution. This issue highlights the importance of staged patch deployment and testing in enterprise environments.

As threats continue to evolve across multiple attack vectors, security teams must balance the urgency of patching critical vulnerabilities with the stability requirements of production systems. Today's developments underscore the need for comprehensive threat monitoring and rapid incident response capabilities.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Cisco warns of max severity ISE zero-day exploited in attacks
CVE7
Chinese hackers use SparroWocky malware in govt espionage attacks
Malware2
  • SparroWocky
    New backdoor malware used by FamousSparrow
  • SparrowDoor
    Previously used backdoor malware by FamousSparrow
IP Address16
  • 185.199.108.154
    C2 IP address
  • 185.199.109.155
    C2 IP address
  • 185.199.110.155
    C2 IP address
  • 185.199.111.155
    C2 IP address
  • 185.199.108.156
    C2 IP address
  • 185.199.109.156
    C2 IP address
  • 185.199.110.156
    C2 IP address
  • 185.199.111.156
    C2 IP address
  • 185.199.108.153
    C2 IP address
  • 185.199.109.153
    C2 IP address
  • 185.199.110.153
    C2 IP address
  • 185.199.111.153
    C2 IP address
  • 185.199.109.154
    C2 IP address
  • 185.199.110.154
    C2 IP address
  • 185.199.111.154
    C2 IP address
  • 185.199.108.155
    C2 IP address