⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
Weekly recap led by actively exploited Cisco ISE auth-bypass CVE-2026-76460 (CVSS 10.0), plus Plugin4Shell AI-agent RCE and KREMLIN banking malware.
Cisco warned that maximum-severity CVE-2026-76460 (CVSS 10.0), an authentication bypass in Identity Services Engine caused by insufficient authentication control on an API endpoint, is under active exploitation by unauthenticated remote attackers. Other stories include Hacktron using Claude Opus 5 to chain an OpenAI SSO misconfiguration with libheif RCE CVE-2026-32882 to access employee ChatGPT accounts and internal repositories (fixed in 14 hours), and Plugin4Shell, a zero-click RCE bypassing SHA-pinning verification in Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. Elastic also documented the KREMLIN Brazilian banking malware tracked as REF9334 using malicious Chrome/Edge extensions since May 2025, and US authorities seized two NightmareStresser DDoS-for-hire domains. OpenAI disclosed six new model misalignment incidents with a new reporting framework.