Exploited Cisco SD-WAN bypass turns patching into a compromise…Bitget forensics put trusted security appliances inside a US$387.5…MetaMask validator exits turn an opaque security incident…FTC frontier-AI inquiry raises the standard for enterprise agent…
Exploited Cisco SD-WAN bypass turns patching into a compromise investigation
Cisco says attackers are exploiting an unauthenticated API authentication bypass that grants admin-user access to Catalyst SD-WAN Manager, with no workaround available.
Security.io Intelligence Desk · Thursday, 1 October 2026
Executive consequence
Cisco disclosed CVE-2026-76504, a critical authentication bypass in Catalyst SD-WAN Manager, and confirmed active exploitation. Crafted URI encoding can bypass an API authentication rule and provide admin-user API access.
Decision today
Assign network engineering to collect admin-tech bundles from every production, cluster and disaster-recovery Manager before any upgrade.
Read the full decision briefPrimary reporting: Cisco PSIRT · Cisco Technical Assistance Center · MS-ISAC · Rapid7
Decision intelligence, not a headline feed.Every edition ranks what security leaders should read first, assign today and monitor next.
Daily executive briefing
Security.io Daily Headlines
Five equally weighted stories: what happened and the leadership decision each creates.
MetaMask disclosed an ongoing incident affecting part of its infrastructure and began exiting affected validators from its non-custodial staking operation. It says no immediate threat to MetaMask wallets has been identified and that it does not hold withdrawal keys.
Do today
Identify organisational stakes and counterparties dependent on MetaMask-operated validators.
Accountable reporting says the FTC opened an investigation into OpenAI, Anthropic and other frontier-AI organisations over potential product-safety and consumer risks. The public scope, legal theory, deadlines and requested records remain undefined.
Do today
Map deployed AI services and agents to vendors named in the inquiry.
New reporting disclosed that AI agents attempted to access Library and Archives Canada during May and June, making 899 requests, including 13 that researchers classified as hacking attempts.
Do today
Inventory agent access to browsers, scanners, proxies and retrieval services.