Search

Find merged stories by title or summary.

Breaches & Ransomware
Emerging1 src

🏴‍☠️ Spacebears has just published a new victim : Tomix / Grupo JOPER

Tomix – Indústria de Equipamentos Agrícolas e Industriais, Lda. is a Portuguese manufacturer of crop-protection equipment, best known for agricultural sprayers, atomizers, dusters and related machinery. Founded in 1924 near Torres Vedras by Francisco Xavier Damião, it grew into a market leader in Portugal for plant-treatment equipment, including rotomoulded tanks and high-pressure washers. Since 1997 Tomix has been majority-owned by JOPER – Indústria de Equipamentos Agrícolas, S. A. , and today it operates as part of the family-run JOPER Group alongside JOPER and Ribatejo. Together they supply complementary agricultural machinery for transport, soil tillage and crop treatment across Iberia and export markets https://tomix. com. pt/

·Ransomware.live
Read →
Threat Actors & Campaigns
Emerging1 src

OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems

OpenAI and the Ukrainian government have agreed to a partnership that will provide AI tools and subsidized computing resources to better protect the nation’s critical infrastructure from cyberattacks. The agreement, announced Wednesday at OpenAI’s New York office, will provide Ukrainian cybersecurity officials with access to advanced AI models designed for cybersecurity work through the company’s Daybreak program. OpenAI said it is also pledging over $1 billion in subsidized tokens to support the initiative. During a panel discussion Dmytro Kushneruk, consul general of Ukraine in San Francisco, outlined how the tools would be used for cybersecurity automation, including functions such as incident response, threat triaging, login analysis, inventorying systems, code analysis and validating vulnerabilities.

·CyberScoop
Read →
Threat Actors & Campaigns
Emerging1 src

This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.

·The Hacker News
Read →
AI Security
Emerging1 src

Claude Founder House San Francisco - Anthropic

Claude Founder House San Francisco  Anthropic

·Anthropic (security & safety)
Read →
Threat Actors & Campaigns
Emerging1 src

AI malware just removed the human from the attack loop

Attackers using AI have greatly benefited when it comes to speed and scale, and now, says Cisco Talos, the technology has evolved to execute large portions of the attack chain entirely without human involvement. Researchers at the threat intelligence group have identified what they call the first “LLM-as-C2” architecture that can fully automate the command-and-control (C2) chain. Dubbed CLOSEDQUORUM, the malware binary relies on a panel of large language model (LLM) judges to map and execute the optimal path to steal credentials. “This is not merely augmenting what an operator can accomplish in a session, but transferring an entire phase of the attack from the operator to the system,” Cisco Talos security and threat researcher Ryan Fetterman explained in a blog post . The benefits of speed and scale are compounded because the human-in-the-loop is no longer the bottleneck, he noted.

·CSO Online
Read →
Vendors & Market
Emerging1 src

Apple Maps & Apple Podcasts join forces for Hidden Histories guides & episodes

Apple Podcasts has launched the Hidden Histories guides in Apple Maps , giving listeners a new way to find podcast episodes tied to landmarks and lesser-known locations in five major U. S. cities. Hidden Histories A new Apple Maps guides collection covers San Francisco, Los Angeles, New York City, Chicago, and Washington, D. C. Each guide connects places in Apple Maps with podcast episodes about the history, architecture, and people behind them. Listeners can browse the full Hidden Histories collection or find individual city guides by searching for "Apple Podcasts" in Maps. It is yet another example of Apple using platform synergy to connect users of one service to another. Continue Reading on AppleInsider • Discuss on our Forums

·AppleInsider
Read →
AI Security
Emerging1 src

CAIRN – A New Tool to Track AI Malware That Operates Without Human Control

Cisco Talos has released CAIRN, an open-source toolkit designed to hunt, classify, and track AI-integrated malware by examining the digital markers developers leave behind. The Cognitive Artifact Intelligence Research Network searches for prompt templates, provider endpoints, API-key prefixes, jailbreak terms, and orchestration logic without downloading or executing binaries. The launch also revealed CLOSEDQUORUM, which Talos describes as the first publicly documented Windows implant to delegate tactical command-and-control decisions to artificial intelligence. Instead of awaiting instructions from a human operator or dedicated C2 server , the malware consults up to four commercial large language models—DeepSeek, Qwen, Mistral, and Google Gemini and uses plurality voting to choose its next action. Talos has not confirmed real-world deployment, and the public build is nonfunctional.

·Cyber Security News
Read →
Threat Actors & Campaigns
Emerging1 src

Researchers uncover malware that uses AI to choose its next move

To help security practitioners catch malware that leans on AI, researchers from Cisco Talos shared an open-source framework that they hope will be used to classify and analyze the threat. The tool, called CAIRN, works entirely from metadata pulled off files. No downloading the malware, no running it. CAIRN explorer connects malware binaries by metadata attributes like submitter, import hash, domain or AI provider (Source: Cisco Talos) How CAIRN hunts Researchers look for what Talos … More → The post Researchers uncover malware that uses AI to choose its next move appeared first on Help Net Security .

·Help Net Security
Read →
Phishing
Emerging1 src

The Closed Quorum: Inside the first reported autonomous AI C2 implant

• CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project , exhibits fully autonomous command and control (C2). While we do not have confirmation of in-the-wild deployment, artifacts from the binary were used to connect the developer to postings on criminal forums related to carding, dating back to 2025. • This malware is a useful reference example of how attackers can collapse the decision space of a particular attack phase into a constrained set of choices, allowing AI models to provide reasoning and act independently. • CLOSEDQUORUM represents a shift in effort displacement for attackers, in which expanding portions of the attack chain can be executed without operator involvement. AI’s impact on offensive cyber operations has thus far mainly focused on two dimensions: speed and scale .

·Cisco Talos
Read →
Threat Actors & Campaigns
Emerging1 src

Introducing CAIRN: Frontier tracking for AI-integrated malware

A cairn is a marker left behind on a trail, a deliberately placed stack of stones that helps hikers find their way when the path is unclear. Attackers building AI-integrated malware unintentionally (and inevitably) leave behind markers of their own: prompt templates, provider endpoints, API keys, jailbreak terms, and other artifacts embedded throughout their tooling. When we consider these strings as cognitive artifacts , or vestiges left behind from AI integration, we can enable a new, metadata-first hunting methodology for AI-integrated malware that is fast and scalable. These artifacts can be extracted, related, and classified without ever touching the underlying binary. Today, Cisco Talos is releasing this methodology in the form of CAIRN (Cognitive Artifact Intelligence Research Network), a research toolkit for hunting, classifying, and tracking emerging AI-integrated malware.

·Cisco Talos
Read →
Threat Actors & Campaigns
Emerging1 src

A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight

Cisco Talos researchers created a new framework for identifying malware and hacking tools that rely on AI chatbots—and quickly discovered something unusual.

·WIRED Security
Read →
Vulnerabilities & Patches
Emerging1 src

ZDI-26-719: Cisco ThousandEyes Virtual Appliance DHCP Client Command Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco ThousandEyes Virtual Appliance. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7. 2. The following CVEs are assigned: CVE-2026-20350.

·Zero Day Initiative (Published)
Read →
Vulnerabilities & Patches
Emerging1 src

⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks

A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

Weekly Cybersecurity Newsletter Bulletin – Cisco and Android 0-Day, BragJack Attack, Claude Opus 5 Used to Hack OpenAI, and 20+ Stories

This week’s roundup covers a maximum-severity Cisco ISE zero-day under active exploitation, an actively exploited Android modem flaw on Pixel devices, a browser-extension attack that hijacks AI agents across five browsers, and researchers using Claude Opus 5 to compromise OpenAI’s forum and reach its internal source code. Also inside: a WordPress one-click RCE chain, an unpatched Steam privilege-escalation zero-day, a Microsoft 365 phishing kit that beats MFA in 78 seconds, Apple’s 273-vulnerability patch marathon, and more. Critical Vulnerabilities and Zero-Days Cisco Warns of Critical ISE 0-Day Vulnerability Exploited in Attacks Cisco issued an urgent advisory for CVE-2026-76460, a maximum-severity (CVSS 10. 0) authentication-bypass flaw in Cisco Identity Services Engine (ISE) and ISE-PIC that is already being actively exploited.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

Week in review: Cisco patches exploited email gateway 0-day, Revolut breach

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: What we know about the Revolut data breach so far Someone impersonating a government agency, using an email address on that agency’s domain, obtained sensitive customer records from Revolut. The bank confirmed the incident on Saturday, September 12. DeepZero: Open-source hunting for vulnerable Windows drivers DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. You … More → The post Week in review: Cisco patches exploited email gateway 0-day, Revolut breach appeared first on Help Net Security .

·Help Net Security
Read →
Breaches & Ransomware
Emerging1 src

The Cisco root route.

Cisco patches a maximum-severity vulnerability in its Identity Services Engine. Court documents describe AI as “an astonishing theft of unprecedented proportions.” Researchers chain vulnerabilities to take over employee ChatGPT accounts. Microsoft and Check Point patch vulnerabilities. Manufacturing remains ransomware’s favorite target. Hackers compromise a Japanese image-sharing service. The Settra ransomware group leverages remote management software. An Australian think-tank warns of Chinese AI-enabled surveillance in Venezuela. Maria Varmazis joins me for a look back at ten years of critical infrastructure exploits. Everything you wanted to know about AI but were afraid to prompt. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing , and you’ll never miss a beat .

·The CyberWire
Read →
Vulnerabilities & Patches
Emerging1 src

Cisco Zero-Day Highlights API Endpoint Authentication Issues

The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.

·Dark Reading
Read →
DFIR
Emerging1 src

InfoSec News Nuggets – 09/18/2026

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks A maximum-severity flaw in Cisco Identity Services Engine and ISE-PIC, tracked as CVE-2026-76460, is being actively exploited to bypass authentication on the web management interface through a crafted request to an insufficiently protected API endpoint, potentially handing attackers root-level command execution. Cisco has released patched versions across the 3. 1 through 3. 5 branches and warns there are no workarounds, only mitigations like restricting management traffic with access control lists, while CISA has ordered federal agencies to patch by September 19.

·AboutDFIR
Read →
Vulnerabilities & Patches
Emerging1 src

ZDI-26-717: Cisco Identity Services Engine AlarmMessageDiskQueue Deserialization of Untrusted Data Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7. 2. The following CVEs are assigned: CVE-2026-20211.

·Zero Day Initiative (Published)
Read →
Vulnerabilities & Patches
Emerging1 src

ZDI-26-718: Cisco Identity Services Engine MnTRESTLivelogService XML External Entity Processing Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4. 9. The following CVEs are assigned: CVE-2026-20235.

·Zero Day Initiative (Published)
Read →
Vulnerabilities & Patches
Emerging1 src

ZDI-26-716: Cisco Identity Services Engine createDBLink Command Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7. 2. The following CVEs are assigned: CVE-2026-20176.

·Zero Day Initiative (Published)
Read →
Vulnerabilities & Patches
Emerging1 src

Cisco patches max-severity ISE flaw, the second critical zero-day this week

Cisco released patches for an actively exploited authentication bypass vulnerability in its Cisco Identity Services Engine (ISE) platform, which is used for enterprise network access control and policy enforcement. This is the second zero-day flaw Cisco has been forced to release emergency patches for this week, after fixing a critical vulnerability in its Secure Email Gateway appliance . The Cisco ISE flaw, tracked as CVE-2026-76460 , has the maximum severity score of 10. 0 on the CVSS scale and can be exploited without authentication to gain root-level privileges on the device. The vulnerability is in an API endpoint used for management and can be exploited by sending crafted requests that bypass the normal web-based management interface completely. The flaw affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC) in all configurations and was fixed in versions 3.

·CSO Online
Read →
Vulnerabilities & Patches
Emerging1 src

Cisco alerts customers to second actively exploited zero-day in as many days

Cisco disclosed its second actively exploited zero-day vulnerability in as many days, presenting its customers with back-to-back threats to address in unrelated products. The latest zero-day — CVE-2026-76460 — has a maximum-severity rating and was exploited before Cisco disclosed and patched the vulnerability Wednesday. The defect in an API of Cisco Identity Services Engine (ISE) allows a remote attacker to bypass authentication and gain full control of the affected device. “ISE devices enforce network access policy, so root access on the appliance lets an attacker modify that policy, extract stored credentials, delete logs, and move laterally into every network segment ISE controls,” Landon Rice, senior exploit developer at VulnCheck, told CyberScoop.

·CyberScoop
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-76460: A critical Cisco ISE authentication bypass under active exploitation

A critical vulnerability, CVE-2026-76460, affecting Cisco ISE & ISE-PIC is being actively exploited. Read more for technical details & impact to organizations. CVE-2026-76460: Cisco ISE Authentication Bypass Exploitation

·Malware.news
Read →
Vulnerabilities & Patches
Emerging1 src

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution. The post Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard appeared first on SecurityWeek .

·SecurityWeek
Read →
Vulnerabilities & Patches
Emerging1 src

Cisco Warns of Active Exploitation of Critical ISE Flaw

Cisco urged ISE customers to apply a software update, as well as check for signs of exploitation

·Infosecurity Magazine
Read →
Vulnerabilities & Patches
Emerging1 src

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

Two days after it warned customers about an actively exploited email gateway zero-day, Cisco confirmed one more flaw is being targeted: CVE-2026-76460, an authentication bypass bug in an API of Cisco Identity Services Engine (ISE). About CVE-2026-76460 Cisco ISE is an identity-based network access control and policy platform. It checks connecting users’ identity, profiles devices and checks their security posture, grants users the right type of access, and logs it all. “[CVE-2026-76460] is due to … More → The post Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) appeared first on Help Net Security .

·Help Net Security
Read →
Vulnerabilities & Patches
Emerging1 src

Cisco’s rough week: maximum severity zero-day hits network access control - Cybernews

Cisco’s rough week: maximum severity zero-day hits network access control Cybernews

·Cybernews
Read →
Vulnerabilities & Patches
Emerging1 src

U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog

U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added [ 1 , 2 ] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2026-76460 (CVSS score of 10.0) Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability • CVE-2026-87886  (CVSS score NA) Acronis Backup Incorrect Default Permissions Vulnerability • CVE-2026-58704  (CVSS score of 8.8) Google Pixel Improper Authorization Vulnerability CVE-2026-76460 is an authentication bypass vulnerability affecting an API in Cisco Identity Services Engine (ISE). The flaw is caused by inadequate authentication checks on a specific API endpoint.

·Security Affairs
Read →
Vulnerabilities & Patches
Emerging1 src

Cisco warns of max severity ISE zero-day exploited in attacks

Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [... ]

·BleepingComputer
Read →
Vulnerabilities & Patches
Emerging1 src

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. "This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

Hackers exploit zero-day flaw in Cisco email gateway

Researchers warn the vulnerability could be used by state-linked actors for espionage.

·Cybersecurity Dive
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-76460 Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability • CVE-2026-87886 Acronis Backup Incorrect Default Permissions Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.

·CISA Alerts
Read →
Vulnerabilities & Patches
Emerging1 src

Hacked by email: attackers exploiting critical zero-day in Cisco’s secure email solution - Cybernews

Hacked by email: attackers exploiting critical zero-day in Cisco’s secure email solution Cybernews

·Cybernews
Read →
Vulnerabilities & Patches
Emerging1 src

ZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Secure Firewall Management Center. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8. 1. The following CVEs are assigned: CVE-2026-20242.

·Zero Day Initiative (Published)
Read →
Vulnerabilities & Patches
Emerging1 src

Critical Cisco Secure Email Gateway zero-day gives attackers root access

Cisco released emergency patches for a critical vulnerability in its Secure Email Gateway appliance that could allow attackers to take over the device by simply sending malicious crafted emails to users. The flaw was already being exploited in the wild when the fixes were released. Tracked as CVE-2026-76461, the vulnerability is described by Cisco as an SQL injection caused by insufficient validation in the product’s email parsing code. Parsing incoming email messages for threats is this appliance’s main job, which means the attack vector is trivial. “An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device,” Cisco said in its advisory .

·CSO Online
Read →
Vulnerabilities & Patches
Emerging1 src

Cisco users urged to patch email gateway flaw

Cisco warns defenders to patch a critical vulnerability in its Secure Email Gateway appliance that may be used by attackers to gain root privileges

·ComputerWeekly Security
Read →
Vulnerabilities & Patches
Emerging1 src

Cisco warns customers of actively exploited zero-day in email gateways

Attackers of unknown origins and motivations are exploiting a critical zero-day vulnerability in Cisco Secure Email Gateway, authorities and researchers said Monday. The vulnerability — CVE-2026-76461 — was exploited before Cisco disclosed and patched the defect Monday and allows unauthenticated, remote attackers to execute commands with root privileges on vulnerable systems. “In practical terms, that gives the attacker control of the gateway itself,” Douglas McKee, director of vulnerability intelligence at Rapid7, told CyberScoop. Cisco said its product security incident response team became aware of active exploitation of the defect affecting Cisco AsyncOS Software for Cisco Secure Email Gateway in September. When asked for further details, a company spokesperson pointed to the advisory and reiterated that the company is aware of active exploitation of the vulnerability.

·CyberScoop
Read →
AI Security
Emerging1 src

Splunk Conf 26: Splunk hopes to build confidence in agentic AI

With trust in AI agents close to rock bottom in the popular imagination, Splunk and Cisco unveiled a series of platform enhancements designed to enhance observability and confidence in agentic AI

·ComputerWeekly Security
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild

Overview On September 14, 2026, Cisco published a security advisory for CVE-2026-76461 , a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3. 1 base score of 9. 8 and could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance. Cisco Secure Email Gateway, formerly known as IronPort Email Security Appliance, is an enterprise email security product that inspects inbound and outbound email for threats including phishing, malware, spam, and business email compromise. Because affected gateways process externally delivered email as part of their normal operation, exploitation does not require access to an administrative interface or authentication.

·Rapid7 Blog
Read →