Zero-Day Exploits Target Cisco ISE and Android Pixels as AI‑Driven Browser Hijack Surfaces
A critical vulnerability in Cisco Identity Services Engine (ISE) that allows unauthenticated remote code execution is now being actively weaponised, security teams say, while a separate flaw in the modem firmware of Google Pixel phones is also under exploitation in the wild.
The Cisco issue, classified as maximum severity, affects the core authentication platform used by enterprises to enforce network access policies. Researchers have observed threat actors leveraging the bug to gain privileged footholds within corporate environments, prompting urgent advisories from Cisco and calls for immediate patching. The vendor has released a software update, but the rapid adoption of the exploit underscores the challenges of defending legacy network infrastructure.
In parallel, a zero‑day affecting the Android baseband on Pixel devices enables attackers to execute arbitrary code through crafted cellular signals. The vulnerability, discovered in the modem's firmware, bypasses typical Android security layers because it operates below the operating system. Google has issued a security bulletin and is rolling out patches, yet the exploit's active use means many users remain exposed until updates reach all carriers and devices.
Adding to the threat landscape, security researchers have uncovered a browser‑extension attack dubbed "BragJack" that hijacks AI agents embedded in five major browsers. The malicious extension intercepts prompts sent to generative AI services, rerouting them to attacker‑controlled endpoints. By manipulating the AI’s responses, the attack can exfiltrate data or deliver misinformation without the user’s knowledge. The technique highlights emerging risks as AI assistants become more integrated into everyday browsing tools.
In a separate development, a research team demonstrated the offensive potential of Anthropic's Claude Opus 5 model by using it to compromise OpenAI’s systems. By prompting Claude to generate code snippets and exploit scripts, the team was able to bypass certain defensive measures, illustrating how advanced language models can be repurposed for malicious ends. The findings have spurred calls for stricter usage policies and better monitoring of AI‑generated content in security‑critical contexts.
These incidents arrive amid a broader surge in high‑impact vulnerabilities, with more than twenty notable security stories reported this week. Experts warn that the convergence of network, mobile, and AI attack vectors demands coordinated defensive strategies, faster patch deployment, and heightened awareness among both IT professionals and end users.
Organizations are urged to prioritize the Cisco ISE and Pixel modem patches, scrutinize browser extensions for anomalous permissions, and implement robust monitoring of AI interactions. As threat actors continue to exploit zero‑day flaws and AI capabilities, the cybersecurity community emphasizes proactive measures to mitigate damage before widespread compromise occurs.
Comments (0)
Be the first to comment.
Join the discussion