O week in review: active zero-days, AI agent exploitation and browser hijacks
A Cisco alert warned that a fresh maximum‑severity flaw in its Identity Services Engine (ISE) is already being exploited in the wild. The vulnerability, tracked as CVE‑2026‑76460 with a CVSS score of 10.0, lets an unauthenticated remote attacker bypass authentication by sending a crafted request to an affected API endpoint. The issue stems from insufficient authentication controls on a web‑based management interface, granting unauthorized device access to anyone who manages the request.
Enterprise environments are increasingly relying on AI agents that can read and act on sensitive data, yet many security teams lack clear visibility and governance over those tools. Attackers have started using AI to speed up reconnaissance, compromise identities and escalate privileges, making runtime identity controls essential for defense.
ClickFix attacks made a noticeable comeback this week, exploiting seemingly routine browser prompts that users often accept without scrutiny. The tactic tricks victims into executing malicious scripts under the guise of routine browser actions, highlighting how familiar interfaces can become attack vectors.
Other high‑severity issues dominated the vulnerability roundup. Notable entries include CVE‑2026‑58138 (Orkes Conductor), CVE‑2026‑58704 (Google Pixel), CVE‑2026‑90894 aka ParaShells (Parallels Desktop), CVE‑2026‑82079 (Nintendo Switch), CVE‑2026‑89049 (AWS Systems Manager Agent), CVE‑2026‑43502 aka ZcopyReaper, CVE‑2026‑80844 aka DirtyAH6, CVE‑2026‑81000 aka TUNderflow, CVE‑2026‑68121 aka PPPoEject, CVE‑2026‑74469 aka DiagSpill (Linux kernel), CVE‑2025‑43936 (Dell ObjectScale and Elastic Cloud Storage) and many more spanning vendors such as Okta, Palo Alto Networks, Google Chrome, Mozilla Firefox, TP‑Link, Apache Syncope, HPE Networking, Ghostscript, Apple, Check Point and Docker. The sheer volume illustrates how quickly unpatched flaws can be weaponized.
Rachael Saffer sits down with Hannah Hardee, a Cybersecurity Analyst at Southwest Airlines, to discuss moving beyond one‑off training sessions toward a lasting security culture. The conversation emphasizes practical steps that can make defensive measures stick across large, complex organizations.
The overarching lesson this week is simple: trust less, verify more. Even trusted tools, login flows or cloud configurations can hide weak spots, and old malicious payloads often resurface. Rapid patch cycles are now critical, as attackers shorten the window between disclosure and exploitation.
Security teams should prioritize the vulnerabilities marked urgent, monitor exposed systems and adopt continuous verification processes rather than assuming that routine components are harmless. The speed of modern attacks means that the next entry point could be just a single unchecked permission or outdated library.
With AI agents expanding their reach and attackers leveraging the same technology, organizations must pair automation with robust governance to keep sensitive assets protected.
Com informações de: The Hacker News