⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
Weekly recap covers Cisco 0-day, AI agent RCE, ClickFix attacks, and browser hijacks.
Summary
This week's cybersecurity recap highlights several critical vulnerabilities and attacks. Cisco issued a warning about a maximum-severity, actively exploited authentication bypass flaw in its Identity Services Engine (CVE-2026-76460). The U.S. seized domains linked to NightmareStresser, a DDoS-for-hire service responsible for numerous attacks. Additionally, a novel AI supply-chain attack, Plugin4Shell, demonstrated zero-click RCE in major AI coding agents by exploiting SHA-pinning bypasses, and OpenAI disclosed new model misalignment incidents.
Full text
⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks Ravie LakshmananSep 21, 2026Cybersecurity News / Hacking A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not always more clarity. Nothing here needs much drama. Just a lot of small doors left open. Here’s what happened. ⚡ Threat of the Week Cisco Warns of Actively Exploited ISE Auth Bypass — Cisco warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. "This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface." Building Security Culture at Scale: Inside Southwest Airlines Security awareness isn't enough anymore. Rachael Saffer talks with Hannah Hardee, Cybersecurity Analyst at Southwest Airlines, about shifting from training to culture change — and what it takes to make security stick across a large, complex organization. Register to Watch ➝ 🔔 Top News U.S. Seizes NightmareStresser Domains Linked to DDoS Attacks — A U.S. court-authorized operation seized two domains associated with NightmareStresser, which offered a distributed denial-of-service (DDoS)-for-hire service. NightmareStresser is assessed to have been used to launch hundreds of thousands of actual or attempted DDoS attacks against victims across the world since 2022. These attacks have targeted educational institutions, government agencies, gaming platforms, and millions of people, the U.S. Justice Department said. Using Claude to Hack OpenAI — Hacktron said it used Anthropic's Claude Opus 5 to chain two critical vulnerabilities – an SSO misconfiguration in OpenAI's identity infrastructure and a libheif RCE in the Discourse community forum (CVE-2026-32882) – to gain unauthorized access to OpenAI employees' ChatGPT accounts and then use them to access internal OpenAI repositories. The issue was fixed 14 hours after responsible disclosure. Upstream, the flaw was fixed in libheif 1.22.0 in May 2026. Plugin4Shell for 0-Click RCE in AI Coding Agents — AIR Security demonstrated a flaw called Plugin4Shell, a zero-click remote code execution (RCE) vulnerability that bypasses SHA-pinning verification in four major AI coding agents: Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. "In this first-of-its-kind AI supply-chain attack, a trusted plugin is silently swapped for a malicious one and auto-installed past the agent's SHA pinning -- a flaw no marketplace can fix, so users must update their agent," AIR Security said. "It is a plugin SHA-pinning bypass: the agent checks out the exact commit the marketplace pinned but never verifies it landed there, so an attacker who controls the plugin's repo makes the checkout resolve to malicious code while the pin still looks honored. The result is zero-click remote code execution across Claude Code, Codex, GitHub Copilot, and Gemini CLI." OpenAI Reveals New Misalignment Incidents — OpenAI disclosed six new instances of "unexpected or concerning model behavior" that took place over the past six months, while sharing a new framework for reporting, tracking, investigating, and disclosing model misalignment in a bid to improve transparency. "As AI systems grow more advanced and more widely deployed, we need to build a broader and better-informed consensus on the progress of alignment research," OpenAI said. "We do not believe that the AI industry has solved alignment and monitoring to a sufficient degree to continue responsibly scaling at maximum speed for much longer." KREMLIN Banking Malware Hijacks Chrome and Edge for Credential Theft — A previously undocumented Brazilian banking malware operation has been found to deliver a toolkit called KREMLIN. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and Microsoft Edge. "The KREMLIN malware ecosystem employs multi-stage JavaScript loaders, custom C++ installers, and malicious browser extensions to steal credentials, session tokens, and sensitive data," Elastic said. The activity is being tracked as REF9334. ️🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-58138 (Orkes Conductor), CVE-2026-58704 (Google Pixel), CVE-2026-90894 aka ParaShells (Parallels Desktop), CVE-2026-82079 (Nintendo Switch), CVE-2026-89049 (AWS Systems Manager Agent), CVE-2026-43502 aka ZcopyReaper, CVE-2026-80844 aka DirtyAH6, CVE-2026-81000 aka TUNderflow, CVE-2026-68121 aka PPPoEject, CVE-2026-74469 aka DiagSpill (Linux kernel), CVE-2026-70416, CVE-2025-43936 (Dell ObjectScale and Elastic Cloud Storage), CVE-2026-68488 (Please Backup Manager), CVE-2026-56711, CVE-2026-73324 (VLC Media Player), CVE-2026-65638 (cPanel ConfigServer Security & Firewall), CVE-2026-85982, CVE-2026-78626, CVE-2026-78623 (Okta), CVE-2026-0310 (Palo Alto Networks PAN-OS), CVE-2026-85061 (MapLibre GL JS), GHSA-rvhw-4hpw-9vrx, GHSA-rrgq-978q-36mq, GHSA-4xhx-8cv5-wh62, GHSA-8v35-895w-232p (ArangoDB), CVE-2026-65812 (Microsoft Teams for Android), CVE-2026-80172, CVE-2026-61410, CVE-2026-80238 (Dell Secure Connect), CVE-2026-18851 (Ivanti Endpoint Manager Mobile), CVE-2026-91721, CVE-2026-91749, CVE-2026-91726, CVE-2026-93374, CVE-2026-93372 (Google Chrome), CVE-2026-92033, from CVE-2026-92005 to CVE-2026-92013, from CVE-2026-92015 to CVE-2026-92020, from CVE-2026-92022 to CVE-2026-92029, from CVE-2026-92034 to CVE-2026-92038 (Mozilla Firefox), CVE-2026-15315, CVE-2026-15316 (TP-Link Tapo cameras), CVE-2026-82232, CVE-2026-77147, CVE-2026-73178 (Apache Syncope), CVE-2026-76669, CVE-2026-76670, CVE-2026-76672, CVE-2026-76673, CVE-2026-76674 (HPE Networking EdgeConnect SD-WAN Gateways and SD-WAN Orchestrator), CVE-2026-73693, CVE-2026-73694, CVE-2026-73698, CVE-2026-73699 (FileRun), CVE-2026-39919 (Ghostscript), CVE-2026-91998 (Casdoor), CVE-2026-91932, CVE-2026-91931 (Flowise), CVE-2026-65400, CVE-2026-65414, CVE-2026-65346, CVE-2026-84607, CVE-2026-43790 (Apple), CVE-2026-90999 (Sentry Seer), CVE-2026-77692, CVE-2026-76163, CVE-2026-19667, CVE-2026-19666, CVE-2026-80274 (ISC BIND 9), CVE-2026-91843 (Check Point), CVE-2026-77179 (Docker), CVE-2026-81642, CVE-2026-82717 (Unbound DNS), Click2Shell (WordPress), CVE-2026-28326, CVE-2026-28323, CVE-2026-28309, CVE-2026-28306, CVE-2026-28308, CVE-2026-28310, CVE-2026-28314, CVE-2026-28313, CVE-2026-28307, CVE-2026-28305, CVE-2026-28317, CVE-2026-28304, CVE-2026-28312, CVE-2026-28316, CVE-2026-28311, CVE-2026-28302, CVE-2026-28321, CVE-2026-28315 (SolarWinds), CVE-2026-89026 (Issabel Framework), CVE-2026-78175 (Tutor LMS), an operating system command injection vulnerability in Dokploy, and a pickle deserialization vulnerability in MLflow. 🎥 Cybersecurity Webinars How to Find and Control AI Agents Before Access Gets Out of Hand → AI agents are getting access to apps, data, credentials, and workflows faster than most teams can govern them. The real problem is not adoption — it is knowing which agents exist, what they can reach, and
Indicators of Compromise
- cve — CVE-2026-76460
- cve — CVE-2026-32882