Cisco confirmed that CVE-2026-76460, an authentication-bypass flaw in an API of Cisco Identity Services Engine (ISE), is being targeted. Cisco ISE is an identity-based network-access-control and policy platform that verifies user identity, profiles devices, checks security posture, grants access, and logs activity.
Why it matters
The source characterizes the activity as unauthenticated attackers bypassing Cisco ISE’s management interface, but the provided evidence does not describe exploitation effects or affected versions.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily
AI & Agents · Certcc Vulnotes
What happened
A vulnerability in MLflow’s dspy and statsmodels model flavors permits unauthorized pickle deserialization execution despite the MLFLOW_ALLOW_PICKLE_DESERIALIZATION safety control. In the dspy flavor, a model path that does not end in .pkl can bypass the control even when the underlying file is a pickle; the statsmodels flavor does not check the control.
Why it matters
The attack path requires write access to a location from which a user obtains MLflow models, and the vulnerability was confirmed against MLflow 3.12.0.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily
Identity · Securityaffairs
What happened
CenterPoint Energy said an unauthorized third party obtained personal information relating to some customers through an external-facing system; the company said its energy services were not affected. A threat actor claimed to have extracted roughly 7.49 million CenterPoint customer records and offered a 2.5 GB archive, but the company has not confirmed that figure or the exact exposed fields.
Why it matters
The claimed access method was an API that allegedly lacked adequate WAF protection, rate limiting and authentication; these details remain attacker assertions rather than confirmed findings.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Evidence is visible. Uncertainty stays visible too.
Baitaphish separates source records from interpretations, labels AI-assisted enrichment, and avoids turning ingestion volume into unsupported claims about threats, prevalence, or risk.