ZeroHour

Search: “control”

4 stories in the last 24h

Why APAC Enterprises Need Real-Time Threat Intelligence as Singapore, Malaysia, and Thailand Tighten Cyber Compliance in 2026

Singapore, Malaysia, and Thailand all tightened cyber compliance in 2026, mandating continuous monitoring and rapid incident reporting for critical infrastructure.

Singapore's CSA issued the Cybersecurity Code of Practice 2026 for Critical Information Infrastructure on 29 July 2026, adding board cyber-resilience duties, annual training, and controls on Interconnected Systems, with most obligations effective by 29 July 2027. Malaysia's Cyber Security Act 2024 requires NACSA-licensed providers, audits, and fast incident notification, with fines up to RM500,000 and up to ten years' imprisonment. Thailand's NCSA cloud security standard has been enforced since 10 September 2026, with a Website Security Standard effective 16 September 2026. The vendor article argues detection speed has become a compliance metric driving demand for real-time threat intelligence.

Cyble · 4h agoPolicy & legal

Cyber Essentials Has Record Year but Takeup Remains Low

UK Cyber Essentials certifications hit a record 61,430 in the year to June 2026, up 20%, but uptake remains low among 5.7 million SMEs.

The UK government awarded a record 61,430 Cyber Essentials certificates between July 2025 and June 2026, a 20% year-over-year increase, including 46,245 basic self-assessed and 15,185 audited CE+ certifications. Roughly three-quarters were recertifications, and uptake remains low against an estimated 5.7 million UK SMEs. An ESET survey found 49% of UK SMEs suffered a cyber incident in the past year, while the Cyber Resilience Pledge and the Cyber Security and Resilience Bill aim to push certification through supply chains.

U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacksnew

The U.S. DoJ seized NightmareStresser DDoS-for-hire domains, disrupting a booter service linked to hundreds of thousands of attacks since 2022.

The U.S. Department of Justice announced a court-authorized seizure of nightmare-stresser[.]com and nightmarestresser[.]org, conducted with the FBI Anchorage Field Office and the Royal Canadian Mounted Police as part of Operation PowerOFF. Searchlight Cyber reported in 2023 that NightmareStresser had over 566,000 registered users and 52 servers, offering Layer 4 amplification and Layer 7 floods against education, government, and gaming victims. The seizure follows earlier actions, including 48 domains seized in December 2022 and 53 domains plus four arrests this April, bringing totals to twelve charged defendants and more than 100 seized domains.

The Hacker Newsupdated · 20m agofirst · 8h agoPolicy & legal 5 sources

CISA decides weekly vulnerability bulletin isn't necessary anymore

CISA will discontinue its weekly vulnerability bulletin on September 28, pushing users toward KEV, alerts, and CVE data under risk-based prioritization.

CISA announced its weekly vulnerability bulletin will stop on Monday, September 28, as part of a shift from static CVSS severity scores to a modern, risk-based approach detailed in a June Binding Operational Directive. The directive prioritizes federal remediation based on exposure, exploitation evidence, control granted by exploitation, and whether exploitation can be automated. CISA directs bulletin subscribers to rely instead on its Known Exploited Vulnerabilities catalog, cybersecurity alerts and advisories, and the CVE catalog, requiring users to enable those subscriptions in GovDelivery or Granicus to avoid missing critical notices.

The Register · Security · 17h agoPolicy & legal