ZeroHour

Daily brief

AI-written briefings built from the classified stories, KEV additions, high-risk CVEs, incidents and model releases. Daily every morning; weekly recap on Mondays.

daily2026-09-18covers generated glm-5.3-flash

Top story

Cisco emergency-patched an actively exploited CVSS 10.0 zero-day in Identity Services Engine: CVE-2026-76460 is an unauthenticated API authentication bypass granting root command execution on ISE and ISE-PIC in all configurations. CISA added it to KEV with a federal patch deadline of September 19; no workarounds exist. It is Cisco's second actively exploited zero-day this week, after CVE-2026-76461 in Secure Email Gateway.

Exploitation & threats

Patch priorities

  • Cisco ISE/ISE-PIC (CVE-2026-76460): update to fixed releases across the 3.1–3.5 branches (e.g., 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12) and re-image suspect nodes; Cisco's broader batch also fixes dozens of FMC, ISE, and Nexus Dashboard flaws.
  • CVE-2026-76461 (CVSS 9.8, public PoCs): unauthenticated RCE via email parsing in Secure Email Gateway and Secure Email and Web Manager — patch urgently.
  • CVE-2026-85706 (CVSS 10.0, EPSS 12%, 11 PoCs): GitLab CE/EE flaw fixed in 19.1.8, 19.2.6, and 19.3.2 — upgrade self-managed instances.
  • Plugin4Shell: a zero-click RCE via a plugin SHA-pinning bypass affects Claude Code, OpenAI Codex, Gemini CLI, and Copilot; Anthropic and OpenAI shipped fixes, Microsoft and Google have not.

Breaches & incidents

  • Gyazo: Helpfeel disclosed that a compromised image-upload server exposed ~23.62M user records (names, emails, password hashes, session IDs, X integration tokens) and ~490M image metadata records, mostly pre-January 2019; leaked 32-character image IDs could enable unauthorized image access.
  • Navigate360: a hacktivist exfiltrated 8.3M anonymous tips from school, community, and Crime Stoppers tip platforms in April 2026 — no individual notifications have gone out six months later.
  • Ransomware: 22 leak-site posts in 24 hours, including Pertamina (RansomHouse) and AECOM (Brain Cipher), plus new Qilin, Akira, krybit, and Inc Ransom listings.

AI

Watchlist

  • Verify ISE patch coverage and review access.log for unexpected API requests before the September 19 KEV deadline.
  • Audit sites embedding Brevo/Sendinblue scripts for f.js calls to sendibt1.com subdomains (IOCs).
  • vm2 remains escape-prone: incomplete fixes leave CVE-2026-92937 and CVE-2026-92955 (both CVSS 10.0) open in Node sandboxes.
  • Apply Microsoft's fix for Azure Billing CVE-2026-62874 (CVSS 10.0), which permits network-based privilege elevation.
  • Tanker boarding investigations may reshape maritime OT guidance — watch for Coast Guard Cyber Command findings.

Stories in this brief