Daily Briefing
Today's outlook
Cisco Rushes Emergency Patch for Actively Exploited ISE Zero-Day as Apple Ships Six Critical macOS Fixes
Good morning. SecurityWeek reported that Cisco has issued an emergency patch for a zero-day in Identity Services Engine (ISE) that is under active exploitation. According to SecurityWeek, remote, unauthenticated attackers can exploit the flaw to bypass authentication using crafted requests. Organizations running ISE should apply Cisco's emergency patch as a priority, given the combination of no authentication requirement and confirmed in-the-wild exploitation.
Apple has also pushed fixes for six critical macOS vulnerabilities, per the vendor's advisories. Five of the six affect macOS 15.0 up to the fix delivered in 15.8; the sixth, CVE-2026-84520, affects macOS from its earliest version up to the fix delivered in 27.0. Four of the six carry a CVSS 3.1 base score of 9.8 or higher: CVE-2026-84561 and CVE-2026-65414 (9.8, network vector, no privileges or user interaction required, full loss of confidentiality, integrity and availability), CVE-2026-84520 (9.8), and CVE-2026-65381 (10.0, with a changed scope). Two more score 9.1: CVE-2026-86881 (confidentiality and integrity impact, no availability impact) and CVE-2026-43790 (integrity and availability impact, no confidentiality impact). None of the six appear on CISA's Known Exploited Vulnerabilities catalog. Apple's advisories direct affected users to the vendor's published guidance and any interim mitigation for the fixed release.
Separately, BleepingComputer reported that Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. Enterprises that have deployed this update should watch for domain authentication failures and follow Microsoft's guidance as the investigation proceeds.
Elsewhere, The Record reported that House Energy and Commerce Chairman Brett Guthrie said action on the FRONTIER Act, federal AI safety legislation, will wait until 2027, saying he did not want to rush it in a lame-duck session. Krebs on Security reported that data broker Radaris lost domains following a lawsuit alleging violations of a New Jersey privacy law. BleepingComputer reported that Anthropic is testing "Claude Money," a feature that would connect Claude directly to users' bank accounts.
Zoom out: The day's advisories arrive alongside a separate discussion of AI systems gaining broader access and autonomy — Anthropic testing bank-account access for Claude and The Register covering AI agents that modify themselves without being told to — a reminder that access-control questions are widening beyond traditional network infrastructure.
Vulnerability in focus
CVE-2026-86881 — Apple. CVSS 9.1
Affected: macos.
What to do: Follow the vendor advisory for the fixed release and any interim mitigation.
What we're tracking
- SecurityWeek: Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day Read it
- Help Net Security: Riverbed NPM 360 uses AI to predict and prevent network disruptions Read it
- BleepingComputer: Anthropic wants Claude to analyze your bank account and financial data Read it
- The Register: AI agents can modify themselves without humans telling them to do so Read it
Sources
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day SecurityWeek
- Riverbed NPM 360 uses AI to predict and prevent network disruptions Help Net Security
- Anthropic wants Claude to analyze your bank account and financial data BleepingComputer
- AI agents can modify themselves without humans telling them to do so The Register
- Key lawmaker suggests action on AI safety legislation will wait until 2027 The Record
- Data Broker Radaris Loses Domains in Privacy Fight Krebs on Security
- Tuskira Vector brings autonomous red teaming to attack surface validation Help Net Security
- The AI security question leaders should be asking instead Help Net Security
- A flat cybersecurity budget doesn’t have to mean weaker coverage Help Net Security
- AWS’s new sign-up gives accounts spend caps, email invites, and agent-set permissions Help Net Security
- GNOME 51 adds passkey logins, offline maps and drawn PDF signatures Help Net Security
- AI is adding to the review load on open-source projects, many of them thinly funded Help Net Security
- The world must establish red lines for autonomous AI weapons Help Net Security
- Windows 11 KB5124008 update breaks domain trust for some users BleepingComputer
Summarized from the linked reports and the advisory record by the desk. Verify against the original sources before citing.