Weekly Cybersecurity Newsletter Bulletin – Cisco and Android 0-Day, BragJack Attack, Claude Opus 5 Used to Hack OpenAI, and 20+ Stories
Brief
This week’s roundup covers a maximum-severity Cisco ISE zero-day under active exploitation, an actively exploited Android modem flaw on Pixel devices, a browser-extension attack that hijacks AI agents across five browsers, and researchers using Claude Opus 5 to compromise OpenAI’s forum and reach its internal source code.
Also inside: a WordPress one-click RCE chain, an unpatched Steam privilege-escalation zero-day, a Microsoft 365 phishing kit that beats MFA in 78 seconds, Apple’s 273-vulnerability patch marathon, and more.
Critical Vulnerabilities and Zero-Days
Cisco Warns of Critical ISE 0-Day Vulnerability Exploited in Attacks
Cisco issued an urgent advisory for CVE-2026-76460, a maximum-severity (CVSS 10. 0) authentication-bypass flaw in Cisco Identity Services Engine (ISE) and ISE-PIC that is already being actively exploited.
