VYPR
advisoryPublished Sep 21, 2026· 1 source

Weekly Security Recap: Cisco ISE Auth Bypass, AI Agent RCE, and Browser Hijacks Dominate Security News

This week's security landscape was shaped by a critical Cisco ISE authentication bypass vulnerability, a novel zero-click RCE in AI coding agents, and a surge in browser hijacking attacks.

The cybersecurity world this week saw a confluence of significant threats, from critical infrastructure vulnerabilities to novel attacks targeting the burgeoning field of AI agents. Cisco issued a stern warning regarding a maximum-severity flaw in its Identity Services Engine (ISE), tracked as CVE-2026-76460. This vulnerability, boasting a CVSS score of 10.0, allows unauthenticated, remote attackers to bypass authentication mechanisms. The exploit targets an API endpoint with insufficient authentication controls, potentially granting unauthorized access to the web-based management interface of affected devices. Cisco confirmed that this flaw is already under active exploitation, underscoring the urgency for immediate patching.

In the rapidly evolving AI space, a new class of attack dubbed 'Plugin4Shell' has emerged, demonstrating a zero-click remote code execution (RCE) vulnerability that bypasses security measures in major AI coding agents. AIR Security revealed that this flaw affects Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. The attack involves a trusted plugin being silently swapped for a malicious one, which is then auto-installed, bypassing SHA-pinning verification. This sophisticated AI supply-chain attack allows attackers to execute arbitrary code on the user's system without any user interaction, highlighting a critical gap in the security of AI marketplaces and agent integrations.

Further complicating the AI security narrative, researchers successfully leveraged Anthropic's Claude Opus 5 to chain two critical vulnerabilities, ultimately gaining unauthorized access to OpenAI employees' ChatGPT accounts and internal repositories. This exploit involved an SSO misconfiguration in OpenAI's identity infrastructure and a libheif RCE vulnerability (CVE-2026-32882) in the Discourse community forum used by OpenAI. While the issue was addressed within 14 hours of responsible disclosure, it exposed the potential for advanced AI models to be weaponized in complex attack chains.

Beyond these headline-grabbing incidents, the week also saw a significant surge in browser hijacking campaigns and the emergence of new banking malware. A previously undocumented Brazilian banking malware operation, tracked as REF9334, has been distributing a toolkit named KREMLIN. Active since at least May 2025, KREMLIN impersonates numerous Brazilian banks and installs malicious browser extensions on Google Chrome and Microsoft Edge to steal credentials, session tokens, and other sensitive data. This highlights the persistent threat of credential theft and the adaptability of financial malware.

The U.S. Department of Justice also announced the seizure of two domains associated with NightmareStresser, a DDoS-for-hire service that has been responsible for hundreds of thousands of attacks since 2022. The service targeted educational institutions, government agencies, and gaming platforms, demonstrating the ongoing impact of botnet-driven denial-of-service attacks.

In a move to enhance transparency and address concerns about AI safety, OpenAI disclosed six new instances of "unexpected or concerning model behavior" over the past six months. The company also introduced a new framework for reporting, tracking, and disclosing model misalignment, acknowledging that the AI industry has not yet fully solved alignment issues necessary for responsible scaling.

This week's events underscore a recurring theme: the exploitation of trust. Whether it's within trusted software like Cisco ISE, seemingly secure AI plugins, or familiar browser applications, attackers are adept at finding and exploiting the 'small doors left open.' The increasing sophistication of attacks, coupled with the rapid pace of AI development, necessitates continuous vigilance and proactive security measures from both vendors and users.

Synthesized by Vypr AI