Security
Cisco ISE Zero-Day Exploited; CISA Orders Three-Day Patch
Cisco patches a maximum-severity ISE authentication bypass under active attack as CISA orders federal agencies to fix it within three days.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
Cisco Patches Actively Exploited Maximum-Severity ISE Zero-Day
Cisco released updates for a maximum-severity authentication bypass in Identity Services Engine and ISE Passive Identity Connector that is being actively exploited. Tracked as CVE-2026-76460, the flaw stems from insufficient authentication control on an API endpoint, letting a remote attacker bypass the web management interface and gain unauthorized access regardless of configuration. No workarounds exist. Fixed releases are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4. CISA added the flaw to its Known Exploited Vulnerabilities Catalog and ordered federal agencies to patch within three days. Cisco published indicators of compromise and advised checking access.log files on every node, cross-checking firewall and network logs, and re-imaging suspected nodes.
Cisco warns of max severity ISE zero-day exploited in attacks →
PhantomFix Flaw Hijacks Sentry Seer Autofix Agent
A critical vulnerability in Sentry Seer, the automated analysis and remediation feature in Sentry, lets a remote attacker with no account on the victim’s organization submit a fabricated error report that steers Seer’s autonomous coding agent into fetching and running attacker-controlled code. Tracked as CVE-2026-90999 and CERT/CC note VU#212479, it is named PhantomFix. Frontend error collection relies on a Sentry DSN, public by design, and the sender controls every field of a report. Exposure requires Seer handing issues to a coding agent automatically with automated remediation enabled and frontend errors collected through a public DSN. The same manipulation was run against every leading LLM tested, and each followed it.
PhantomFix: a fabricated bug that hijacks an AI autofix agent (CVE-2026-90999) →
FamousSparrow APT Targets Latin American Governments With SparroWocky
A Chinese cyber-espionage group known as FamousSparrow is using a new backdoor, SparroWocky, to target government agencies and major industries in Central and South America. In July 2025, ESET researchers observed FamousSparrow pivot to exclusively targeting government organizations in Latin America, and the following month it replaced its SparrowDoor backdoor with SparroWocky. The modular C++ program is deployed via DLL sideloading, executes in-memory, encrypts command-and-control traffic, automates self-deletion, and uses stack spoofing. Since August 2025 it has hit government organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela, plus a Puerto Rico telecom. ESET suspects the activity helps China monitor local reactions to US pressures.
China’s FamousSparrow APT Spies on US Politics in Latin America →
Cloudflare Finds Four Malicious JavaScript Campaigns Evading VirusTotal
Cloudflare’s client-side security team disclosed four active malicious JavaScript campaigns targeting online storefronts, with seven of eight payloads carrying no VirusTotal detection and none drawing a malicious verdict from URLScan. Condition-gating keeps code dormant until a qualifying victim arrives, checking device type, local time, geography, referrer tag, session page count, viewport width and network type. One Lnkr-derived payload had been indexed by URLScan for nearly two and a half years with no classification. Cloudflare’s pipeline processes 3.5 billion scripts daily through a graph neural network and LLM triage, catching all four operations in live traffic. Indicators include adtargett[.]com, sdk-amazonaws[.]com and maper[.]info.
Malicious JavaScript Evaded VirusTotal in Seven of Eight E-Commerce Storefront Attacks →