SEPTEMBER 21, 2026
Subscribe
Global Press Media · World Report
Technology

Zero-Day Attacks Hit Cisco ISE and Pixel Phones as AI‑Powered Browser Hijack Emerges

Zero-Day Attacks Hit Cisco ISE and Pixel Phones as AI‑Powered Browser Hijack Emerges

Security teams report that a severe flaw in Cisco Identity Services Engine (ISE) permitting unauthenticated remote code execution is currently being weaponised, and at the same time a distinct defect in the modem firmware of Google Pixel smartphones is being exploited in the wild.

Rated at the highest severity level, the Cisco problem strikes the central authentication system that enterprises rely on to enforce network access rules. Analysts have seen attackers exploiting the defect to obtain privileged positions inside corporate networks, leading Cisco to issue urgent advisories and urge swift patch deployment. Although the company has issued a software update, the swift exploitation of the bug highlights the difficulty of protecting older network infrastructure.

Simultaneously, a zero‑day in the Android baseband of Pixel phones allows adversaries to run arbitrary code via specially crafted cellular signals. This flaw, located in the modem firmware, sidesteps standard Android protections by residing beneath the operating system. Google responded with a security bulletin and is distributing patches, but the ongoing exploitation leaves numerous users vulnerable until the updates are delivered across all carriers and devices.

Further expanding the risk profile, researchers identified a browser‑extension exploit named “BragJack” that commandeers AI agents built into five leading browsers. The rogue extension captures prompts destined for generative AI services and redirects them to servers controlled by the attacker. By altering the AI’s replies, the method can siphon information or spread false data without the user noticing. This approach underscores new dangers as AI assistants become increasingly woven into routine browsing applications.

In another development, a research group showcased the attack capabilities of Anthropic’s Claude Opus 5 model by leveraging it to breach OpenAI’s infrastructure. By instructing Claude to produce code fragments and exploit scripts, the team succeeded in evading specific defenses, demonstrating how sophisticated language models can be turned toward hostile purposes. The results have prompted demands for tighter usage guidelines and enhanced oversight of AI‑generated material in security‑sensitive environments.

These events occur against a backdrop of an escalating wave of high‑impact flaws, with over twenty significant security reports emerging this week. Specialists caution that the merging of network, mobile, and AI attack surfaces calls for coordinated defense tactics, accelerated patch roll‑outs, and increased vigilance from both IT staff and end users.

Companies are advised to give precedence to the Cisco ISE and Pixel modem updates, examine browser extensions for unusual permissions, and establish strong monitoring of AI communications. As adversaries keep leveraging zero‑day weaknesses and AI functions, the security community stresses proactive steps to limit harm before large‑scale breaches take hold.

Editorial Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related