- Critical security issue in Cisco ISE.
- Critical security issue in Cisco ISE.
- Critical security issue in Cisco ISE.
- Previously exploited Cisco ISE zero-day for RCE attacks.
- Maximum severity zero-day vulnerability in Cisco ISE allowing authentication bypass.
- Maximum severity authentication bypass flaw in Cisco ISE.
- Critical security issue in Cisco ISE.
ThreatNoir Afternoon Brief — September 17
Afternoon Review in IT Security — September 17, 2026
The cybersecurity landscape continues to shift rapidly as critical vulnerabilities emerge and law enforcement takes action against established threats. Today's developments span authentication bypass risks, international espionage campaigns, and infrastructure disruptions that demand immediate attention from security teams worldwide.
Cisco Warns of Maximum-Severity ISE Zero-Day Exploited in Attacks
Cisco has released security updates to address a maximum-severity vulnerability in Identity Services Engine that attackers are actively exploiting in the wild. The vulnerability allows for authentication bypass, presenting an immediate risk to organizations relying on Cisco ISE for network access control and identity management. Source: Cisco warns of max severity ISE zero-day exploited in attacks
Multiple CVEs have been assigned to related issues, including CVE-2025-20337, CVE-2026-20176, CVE-2026-20211, CVE-2026-20284, CVE-2026-20307, CVE-2026-76423, and CVE-2026-76460. Organizations running affected versions should prioritize patching to prevent unauthorized access to critical network infrastructure.
US Takes Down NightmareStresser DDoS-for-Hire Platform
The U.S. Federal Bureau of Investigation has seized the domains used by NightmareStresser, one of the world's longest-running distributed denial-of-service platforms. The takedown represents a significant enforcement action against a service that has facilitated thousands of DDoS attacks against targets globally. Source: US takes down NightmareStresser DDoS-for-hire platform
The seized domains nightmare-stresser.com and nightmarestresser.org will no longer be available to threat actors seeking to launch attacks. This action demonstrates continued law enforcement commitment to disrupting criminal infrastructure that enables cyberattacks.
Chinese Hackers Use SparroWocky Malware in Government Espionage Attacks
The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks against government organizations in Latin America. The malware represents an evolution in the group's toolkit and indicates sustained targeting of sensitive government entities in the region. Source: Chinese hackers use SparroWocky malware in govt espionage attacks
Security researchers have identified multiple infrastructure indicators associated with the campaign, including IP addresses across the 185.199.108.0 through 185.199.111.0 ranges used for command and control operations. The deployment of SparroWocky alongside the previously known SparrowDoor malware suggests a coordinated espionage effort targeting high-value government networks.
Microsoft Shares Workaround for Windows Domain Login Issues
Microsoft has provided a temporary fix for a known issue affecting Windows 11 users who cannot log in with valid domain credentials after installing September 2026 security updates. The problem stems from enforcement mode functionality in the latest patches and impacts organizations managing large Windows deployments. Source: Microsoft shares workaround for Windows domain login issues
Organizations experiencing authentication failures should implement Microsoft's recommended workaround while awaiting a permanent resolution. This issue highlights the importance of staged patch deployment and testing in enterprise environments.
As threats continue to evolve across multiple attack vectors, security teams must balance the urgency of patching critical vulnerabilities with the stability requirements of production systems. Today's developments underscore the need for comprehensive threat monitoring and rapid incident response capabilities.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
nightmare-stresser.comSeized domain of NightmareStresser DDoS-for-hire platformnightmarestresser.orgSeized domain of NightmareStresser DDoS-for-hire platform
- SparroWockyNew backdoor malware used by FamousSparrow
- SparrowDoorPreviously used backdoor malware by FamousSparrow
185.199.108.154C2 IP address185.199.109.155C2 IP address185.199.110.155C2 IP address185.199.111.155C2 IP address185.199.108.156C2 IP address185.199.109.156C2 IP address185.199.110.156C2 IP address185.199.111.156C2 IP address185.199.108.153C2 IP address185.199.109.153C2 IP address185.199.110.153C2 IP address185.199.111.153C2 IP address185.199.109.154C2 IP address185.199.110.154C2 IP address185.199.111.154C2 IP address185.199.108.155C2 IP address