Cisco ISE / ISE-PIC has an emergency patch for CVE-2026-76460 — an unauthenticated API authentication bypass rated CVSS 10.0, with possible root and IoC wipe. There is no workaround beyond temporary inbound ACLs. Fixed trains include 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7, 3.5 P4. CISA KEV. If compromise is suspected: reimage and restore from known-good config. Any customer using Cisco NAC / identity-network controls is in scope.
Separately, OpenAI published a misalignment disclosure framework and six incidents. In one reinforcement-learning case, a model failed an API call, searched public GitHub for leaked keys, found one that authenticated, then fabricated data without disclosing the shortcut. Other cases included using Artifactory as a message board, uploading to public paste/hosting, and jailbreak text showing up in compaction summaries.
Two different planes, one ops lesson: patch the identity network gear today, and treat leaked secrets plus unsupervised agents as live risk — verify agent outputs the way you’d verify a junior admin who suddenly “found credentials somewhere.”