Threat Brief — 2026-09-30 — Zero-days and AI Trust Erosion
Executive summary: A critical Cisco SD-WAN Manager zero-day is under active exploitation, granting attackers admin-level access via authentication bypass. Separately, a WordPress core flaw dubbed "Click2Shell" enables forced theme installation as a stepping stone to remote code execution. On the identity front, Microsoft is preparing automatic Entra ID script-injection protections for October. Two analytical pieces—Mandiant's AI-era vulnerability trends and a warning about persistent AI "coworkers" breaking existing identity models—underscore that the attack surface is expanding faster than controls are maturing.
Top items
- Cisco Catalyst SD-WAN Manager zero-day actively exploited. CVE-2026-76504KEV is a critical authentication-bypass vulnerability in Cisco's SD-WAN management platform. Attackers are exploiting it in the wild to escalate to admin privileges. Cisco has released patches. This story was first reported today; the findings include matching advisories from both The Hacker News and BleepingComputer. (src: The Hacker News) (src: BleepingComputer)*
- "Click2Shell" WordPress core vulnerability enables forced theme installation toward RCE. Researchers identified a flaw in WordPress core that lets attackers force-install themes from the official WordPress.org catalogue. Combined with a vulnerability in an installed theme, this chain can lead to remote code execution on the server. First reported today. (src: Xakep)
- Star Blizzard shifts to "RedFlick" phishing to widen CosmicPulse deployment. Russia's Star Blizzard APT has dropped ClickFix-style lures in favour of a new tactic dubbed "RedFlick," targeting Ukrainian-linked NGOs, think tanks, and journalists to deploy the CosmicPulse backdoor. First reported today. (src: Dark Reading)
- Microsoft to block Entra ID external script-injection attacks from October. Microsoft has reminded customers that Entra ID will receive improved protections against external script-injection attacks beginning next month. Organisations relying on Entra ID for authentication should review the upcoming changes and assess impact on existing integrations. (src: BleepingComputer)
- Malicious Custom GPTs deliver RAT via ClickFix lures. Threat actors are publishing malicious Custom GPTs in ChatGPT, disguised as legitimate product offerings, that direct victims to ClickFix-style attack pages to deploy remote-access trojans. Observed by Huntress in late September. First reported yesterday; a second source corroborates today. (src: The Hacker News)
- Mandiant examines vulnerability discovery and exploitation trends in the AI era. Google Threat Intelligence Group published analysis of vulnerability disclosure and exploitation statistics, evaluating how AI is influencing both discovery rates and exploitation timelines. The research suggests AI tooling is accelerating vulnerability research but evidence of novel AI-driven exploitation remains limited. (src: Mandiant Blog)
- Persistent AI "coworkers" break existing identity and access models. A new analysis warns that always-on AI agents with standing access create identity risks that current security frameworks were not designed for. These agents need dedicated identities, scoped permissions, and ownership tracking—treating them as human or service accounts leaves gaps. (src: BleepingComputer)
Themes
AI as both weapon and victim. Three of today's items involve AI-adjacent risk: malicious ChatGPT Custom GPTs weaponising the platform for malware delivery, AI "coworkers" creating unmodelled identity risks, and Mandiant's analysis of AI's effect on vulnerability discovery. The common thread is that AI tooling is expanding the attack surface faster than defensive controls are adapting.
Active exploitation dominates priority. The Cisco SD-WAN zero-day and the WordPress Click2Shell flaw both involve live or near-live exploitation paths. The MikroTik RouterOS vulnerability (CISA-advised since early September) continues to circulate but has no new development today.
