"This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said.
Cisco ISE CVE-2026-76460: an unauthenticated, remotely exploitable bypass
Cisco on Thursday warned of a maximum-severity flaw in Identity Services Engine (ISE) tracked as CVE-2026-76460 and assigned a CVSS score of 10.0. According to Cisco, the flaw "could allow an unauthenticated, remote attacker to bypass authentication" by sending a crafted request to an affected API endpoint and thereby gain unauthorized access to the device's web-based management interface. Cisco described the root cause as "insufficient authentication control on an API endpoint," and reported active exploitation.
Plugin4Shell and AI coding agents: zero-click RCE across Claude Code, Codex, Copilot, and Gemini CLI
AIR Security demonstrated a novel supply-chain attack it calls Plugin4Shell: a plugin SHA-pinning bypass that produces zero-click remote code execution in four major AI coding agents — Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. AIR Security explained the failure mode plainly: the agent checks out the exact commit the marketplace pinned but "never verifies it landed there," allowing an attacker who controls a plugin's repository to resolve the checkout to malicious code while the pin still appears honored. In AIR Security's words, "a trusted plugin is silently swapped for a malicious one and auto-installed past the agent's SHA pinning -- a flaw no marketplace can fix, so users must update their agent."

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageClickFix social engineering: Google Docs, Brevo supply-chain injection, and Google Visualization misuse
ClickFix-style lures — social-engineering overlays that instruct victims to paste and run commands — surfaced repeatedly this week in three distinct forms. Huntress described an attack in which a threat actor sent a link to a real Google Doc that contained a Google Apps Script sidebar. The sidebar displayed a fake decryption-failure message and offered "remediation instructions" that led macOS and Windows targets to install an AMOS infostealer or a PowerShell loader chain. The Apps Script executed client-side in the victim's browser and collected IP, geolocation, and crypto-wallet information.
Separately, Brevo disclosed a supply-chain breach on 14 September 2026 in which an attacker used a compromised Brevo Cloudflare API key to deploy a Cloudflare Worker that injected a malicious script into brevo.com, sibforms.com and three JavaScript files customers embed on their sites. For about five and a half hours the Worker showed selected visitors a fake Cloudflare CAPTCHA that instructed them to paste and run a malicious command. Sansec reported the incident led to a malicious WordPress plugin installed when site admins visited infected sites and to ClickFix overlays shown to visitors — including anyone who clicked unsubscribe links in Brevo-sent emails. Brevo also disclosed an earlier SAML SSO flaw it said was exploited to gain access to 138 accounts; six were used to send phishing emails and 43 had contacts exported, affecting customers including Trezor, CoinTracking, and BitBox.
Finally, Cisco Talos described a cryptocurrency-theft campaign that used the Google Visualization API for command-and-control, fetching obfuscated JavaScript stored in a public Google Sheets document and injecting it into victims' browser sessions. Those actors lured aspiring cybercriminals with faux "leaked vulnerability reports" and convinced targets to paste JavaScript into the Chrome address bar or into the Tampermonkey extension. Talos tied 49 BTC wallet addresses to the campaign, with 24 receiving funds totaling $10,000 as of early August 2026; the campaign dates back to October 2025.
KREMLIN banking malware (REF9334) and browser-extension credential theft
Elastic reported a previously undocumented Brazilian banking malware operation delivering a toolkit called KREMLIN that has been active since at least May 2025. The campaign impersonated about a dozen Brazilian banks and used malicious browser extensions on Google Chrome and Microsoft Edge. Elastic said the ecosystem "employs multi-stage JavaScript loaders, custom C++ installers, and malicious browser extensions to steal credentials, session tokens, and sensitive data." The activity is being tracked as REF9334.
What this means for security teams, procurement leaders, and end users
- Security teams: Patch and mitigate quickly — Cisco flagged CVE-2026-76460 as actively exploited; AIR Security's Plugin4Shell shows agent-side supply-chain integrity checks can be bypassed even when pinning appears present.
- Procurement and platform owners: Watch embedded third-party widgets and API keys — Brevo's Cloudflare API-key compromise injected malicious scripts into more than 100,000 customer sites, showing how a single embedded vendor component can turn into a wide distribution channel for ClickFix-style lures and WordPress installers.
- End users and administrators: Treat browser prompts and instructions to paste commands with extreme skepticism — Huntress, Sansec, and Cisco Talos all describe campaigns that succeed by convincing targets to execute or inject code locally (paste into terminals, the address bar, or browser extensions).
The week's pattern is consistent and straightforward: trusted components — an API endpoint, a plugin checkout, a customer widget, a browser extension — keep becoming the weakest links. Patch what is flagged as exploited, verify third-party distribution channels, and assume that "trusted" does not equal "safe." As the original recap put it, "The lesson this week is pretty basic: trust less, check more."




