CVE Tools

⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks

The Hacker NewsBy The Hacker News

Reported exploitedCisco Identity Services EngineOpenAI ChatGPT

Our summary

Cisco disclosed active exploitation of CVE-2026-76460, a CVSS 10.0 authentication-bypass flaw in Identity Services Engine (ISE) that can give remote unauthenticated attackers access to affected devices. The weekly roundup also covers Plugin4Shell, a SHA-pinning bypass enabling zero-click RCE in Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI, alongside CVE-2026-32882 in Discourse community forum, fixed upstream in libheif 1.22.0. Other incidents include ClickFix campaigns, Brevo's supply-chain compromise, and KREMLIN malware targeting Google Chrome and Microsoft Edge credentials.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store