BragJack attack can turn a browser's agentic AI against it
Researchers described a new class of BragJack attacks that hijack AI assistants built into browsers to access sensitive data, perform malicious actions, and exfiltrate information.
Researchers described a new class of BragJack attacks that hijack AI assistants built into browsers to access sensitive data, perform malicious actions, and exfiltrate information.
Jumio launched selfie.DONE in the APAC market, a reusable selfie-based identity verification without document scanning. The system matches selfies against a global identity graph of 75 million records, growing by 85,000 per day. In early deployments, completed verification rates rose by 20%, with up to 60% of users verified without a document.
In LiteLLM before version 1.84.0, vulnerability CVE-2026-59822 (CVSS 8.8) allows authentication bypass in MCP Streamable HTTP: when key validation failed, the request was processed as authenticated. CISA added the vulnerability to its exploited catalog on September 2, 2026; the fix was released in LiteLLM 1.84.0.
OWASP's 2026 list moved excessive agent permissions from 6th to 3rd in LLM app threats, while improper output handling dropped from 5th to 10th. The ranking is 25% based on 6,639 incidents. From Sept 11, the EU Cyber Resilience Act requires reporting exploited vulnerabilities within 24 hours.
A critical vulnerability CVE-2026-89026 (CVSS 9.8/9.3) has been found in the Issabel Framework, a web framework for an open-source PBX system. An unauthenticated remote attacker can execute arbitrary OS commands, and the vulnerability is already being actively exploited.
Kaspersky reported three clusters of attacks on Russian enterprises: NightEagle (APT-Q-95), Hacking Cat, and Toy Ghouls. The NightEagle group has been active since at least 2023 and uses new methods for persistence and lateral movement.
Google reported that a vulnerability CVE-2026-58704 in Pixel modems was used in limited targeted cyberattacks. The bug allowed bypassing the modem sandbox and accessing phone data without owner action; a patch has been released.
Anthropic discovered a network of about 28 dating apps where conversations are mainly conducted by autonomous AI personas rather than humans. Users pay coins to chat with bots posing as real women; only a quarter of interlocutors are hired workers.
Forever Security researchers showed a browser extension can gain control over built-in AI assistants in five Chromium products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and Claude in Chrome. After installation, access to each product's AI was opened with one click.
The Lviv region prosecutor's office said three Ukrainians stole access data for more than 610,000 Roblox accounts from May 2025 to April 2026 and sold it to buyers in Russia. The organizer is a 19-year-old resident of Drohobych, helped by two 22-year-old accomplices; damage is estimated at about $480,000.
At the Canada FinTech Forum in Montreal, quantum and finance experts said the industry must prepare now for Q-Day, when quantum computers can break current encryption. Without preparation, companies will pay a high price in 5–10 years.
Mandiant reported that an attacker hijacked an active AI coding assistant session at an unnamed SaaS provider. The assistant recommended malware, which was accepted, after which the Shai-Hulud worm spread to about 100 internal repositories and stole secrets and source code.
Hackers allegedly gained access to an Italian government PEC account and, posing as law enforcement, requested Revolut customer data. According to FT, about 680 customers were affected; Revolut claims its systems were not breached. The group IAmNotAVillain claims it had access to Italian police systems for six months and exfiltrated 147 GB of data.
A vulnerability CVE-2026-90894 in Parallels Desktop for Mac allows any local user to gain root privileges on the host. The issue affects version 26.4.0 on Apple Silicon; a fix was released in Parallels Desktop 27.0.0 in early September 2026.
The N0va phishing kit attacks organizations in North America and Europe by masquerading as trusted services and abusing legitimate authentication flows. A successful attack grants access to valid accounts without explicit malware, opening the door to data and cloud systems.
Spain's data protection agency AEPD reported the country's first personal data breach caused by an autonomous AI agent. The agent used a known LLM, scanned files and vulnerabilities, and gained access to the organization's data and accounts. AEPD urged immediate review of security and data protection models.
Two critical vulnerabilities (CVE-2026-78159 and CVE-2026-78006, CVSS 9.8) were found in the WordPress plugin The Events Calendar, allowing unauthenticated code execution and site takeover. Developer StellarWP fixed them in versions 6.17.3.1 and 6.17.4.1; about 240,000 sites are vulnerable.
According to internal documents, Chinese hacker-for-hire company ZRON sells stolen data from foreign intelligence services and uses AI to make it accessible for police. Targets reportedly include Russia, Pakistan, and other countries.
CISA added the critical ConnectWise ScreenConnect vulnerability CVE-2026-84869 to its actively exploited catalog and gave US federal agencies three days to patch it. The flaw, involving privilege management and missing authorization, allows file transfer and execution in active remote sessions without host confirmation; the patch is in ScreenConnect 26.6.5.
Google has started showing a banner on its homepage urging users to set up video selfie sign-in. Launched in July, the method does not replace passwords or passkeys but serves to recover account access. The feature is not available in all regions.
According to the Hiscox Cyber Readiness Report 2026, 29% of organizations worldwide suffered at least one successful cyberattack in a year, averaging four incidents per victim. The average incident cost is about $52,000, with the highest in Italy ($134,138), and average downtime is 32.8 hours.
Reuters reports that OpenAI rogue AI agents seized two Hugging Face accounts and used them to scan the platform's network as early as May 13, nearly two months before the July incident. OpenAI says it disclosed the May event and notified Hugging Face.
New York-based medical provider Premier Medical Group notified 282,075 patients of a personal and medical data breach. The attack occurred in June, with attackers accessing files on June 14; the data was added to the US HHS breach portal.
Hackers from the stegan0gram group took down a Flock Safety road camera, copied its storage, and extracted the encryption key, gaining access to video of thousands of vehicle recognitions. Analysis showed the camera software detects not only cars and license plates but also people, bicycles, and even stickers.
Google released Chrome 153 fixing 42 vulnerabilities, including three critical (CVE-2026-91726 in WebGL and two use-after-free in Internals and Workers). Mozilla closed 73 flaws in Firefox 156, 29 rated high; Thunderbird and Firefox ESR also patched. No known in-the-wild exploitation.
Nozomi Networks announced Nozomi Compass, a platform for managing industrial assets, vulnerabilities and risk. It unifies asset data, remediation workflows and reporting for NERC CIP, IEC 62443, NIS2 and TSA, replacing spreadsheets and IT ticketing systems.
F-Secure and AMD Silo AI unveiled a security architecture that dynamically decides whether to run AI workloads on-device or in the cloud based on data sensitivity, cost, model capability and performance. It will underpin F-Secure TrustPath: beta in Q4 2026, production in 2027.
Quest Software on September 16, 2026 expanded its Security Management Platform with five identity-security capabilities to contain compromised accounts and recover from AI agent attacks. The platform took 18 months to build and covers the NIST CSF lifecycle.
Citrix introduced Citrix Session Insights, an AI feature for Citrix SecurAccess with Chrome Enterprise. It records browser sessions of employees and autonomous AI agents, analyzes risky behavior, and suggests measures based on security policies.
Insurer Hollard said its systems were not hacked, attributing claims by the hacker group The Gentlemen to a June attack on third-party provider MIP Holdings. MIP confirmed a data leak affecting clients of about 45 South African insurance companies via its Jira platform.