NightmareStresser Goes Offline in Global DDoS-for-Hire Crackdown

2026-09-17T14:51:39Z•8f42ad79522f08247ba7cfeed88a15be6b4c3c3fc5d02b051cbab49e363e114c
CVE-2026-58704CVE-2026-76460CVE-2026-76461Acronis BackupBambooTokenCISA KEVChosen BrickCisco ISECisco Secure Email GatewayDDoS-for-hireGoogle PixelIranian surveillance malwareLiteSpeed EnterpriseMQTTOperation PowerOFFactive exploitationcritical infrastructuredata breachmalwareprivilege escalationremote code executionroot accesssupply-chain and account compromisezero-day

What happened

Security Affairs reporting highlights multiple active threats: CISA-listed exploited vulnerabilities in Cisco ISE, Cisco Secure Email Gateway, Acronis Backup, and Google Pixel; a critical Cisco Secure Email Gateway zero-day enabling unauthenticated remote root access; a targeted Pixel modem zero-day; Iranian Chosen Brick surveillance malware; BambooToken malware using MQTT and sideloading; major data exposures involving Revolut customers and CenterPoint Energy; a critical LiteSpeed Enterprise privilege-escalation flaw; and a global crackdown disrupting the NightmareStresser DDoS-for-hire bot.,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
8f42ad79522f08247ba7cfeed88a15be6b4c3c3fc5d02b051cbab49e363e114c
Enrichment time
2026-09-17T14:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.