Cybersecurity intelligence

Know what changed.
Trace why it matters.

A daily, source-linked briefing for security practitioners. Every record carries its publication context, evidence links, and known limitations.

Get Security Weekly by email

Latest security briefing

Security Daily

Read latest edition
Latest signal

High-signal changes

View full briefing →
Security Daily

Identity · Helpnetsecurity

What happened

Cisco confirmed that CVE-2026-76460, an authentication-bypass flaw in an API of Cisco Identity Services Engine (ISE), is being targeted. Cisco ISE is an identity-based network-access-control and policy platform that verifies user identity, profiles devices, checks security posture, grants access, and logs activity.

Why it matters

The source characterizes the activity as unauthenticated attackers bypassing Cisco ISE’s management interface, but the provided evidence does not describe exploitation effects or affected versions.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily

AI & Agents · Certcc Vulnotes

What happened

A vulnerability in MLflow’s dspy and statsmodels model flavors permits unauthorized pickle deserialization execution despite the MLFLOW_ALLOW_PICKLE_DESERIALIZATION safety control. In the dspy flavor, a model path that does not end in .pkl can bypass the control even when the underlying file is a pickle; the statsmodels flavor does not check the control.

Why it matters

The attack path requires write access to a location from which a user obtains MLflow models, and the vulnerability was confirmed against MLflow 3.12.0.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily

Identity · Securityaffairs

What happened

CenterPoint Energy said an unauthorized third party obtained personal information relating to some customers through an external-facing system; the company said its energy services were not affected. A threat actor claimed to have extracted roughly 7.49 million CenterPoint customer records and offered a 2.5 GB archive, but the company has not confirmed that figure or the exact exposed fields.

Why it matters

The claimed access method was an API that allegedly lacked adequate WAF protection, rate limiting and authentication; these details remain attacker assertions rather than confirmed findings.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Curated context

Selected historical incidents

View library →

This is a curated historical collection, not a measure of global incident prevalence.

Build practical skill

Learn from the same evidence discipline

Open learning hub →
Trust through limits

Evidence is visible. Uncertainty stays visible too.

Baitaphish separates source records from interpretations, labels AI-assisted enrichment, and avoids turning ingestion volume into unsupported claims about threats, prevalence, or risk.

Read methodology and limitations →
Your Monday security briefing

BaitaPhish Security Weekly

Get the week's most important security developments by email, with links to the evidence and the narrated edition.

Monday mornings, when a new edition is published.

We’ll email you a link to confirm your subscription.

Explore Security Weekly