BragJack Turns Browser AI Into an Insider Threat
Researchers demonstrated BragJack, a proof-of-concept attack that let one ordinary extension compromise AI-enabled environments in Chrome, Comet, Edge, Opera Neon, and Claude in Chrome. Depending on the product, it could steal files, screenshots, and browsing data, command agents on authenticated sites, or activate Chrome’s camera and microphone.
These were demonstrations, not known attacks, and required a malicious extension to be installed first. Chrome and Edge patches are already available.
Update Chromium-based browsers and remove unvetted extensions. SOC teams should also review AI-agent transcripts for suspicious commands.
ClickFix Turns Victims Into Malware Installers
Attackers reportedly hijacked HBO Max’s verified Reddit account and ran 108 ClickFix ads in 48 hours, steering Mac and Windows users to fake HBO Max, AI tool, and utility downloads. The sites told victims to paste commands into Terminal, Run, or PowerShell—installing infostealers themselves.
Payloads targeted passwords, browser sessions, Apple Notes, Telegram data, and crypto wallets. Reddit paused the ads, but infection totals remain unknown.
Never paste website-provided commands into system tools, even from verified ads. If you already did, run a full security scan, then change important passwords and revoke unfamiliar sessions from a clean device.
HBO Max Reddit Account Used to Push ClickFix Malware
Attackers reportedly compromised HBO Max’s verified Reddit advertising account and used it to push 108 malicious ads over roughly 48 hours.
The ads directed Windows and macOS users to fake sites that used ClickFix techniques to install malware.
This reminds me of a smishing message I received claiming to be about Oprah’s “big giveaway.” Attackers know recognizable names and trusted brands can lower our guard, which is why reputation alone should never be treated as proof that a message, ad, or link is legitimate.
Verify unexpected promotions through the brand’s official website and never run commands provided by an ad, message, or unfamiliar site.
Cisco Email Zero-Day Gives Attackers Root Access
Cisco disclosed an actively exploited Secure Email Gateway zero-day that lets unauthenticated attackers gain root access through a crafted email.
Attackers can exploit the flaw through normal email processing without accessing the management interface.
If an attacker gained root access, I wouldn’t trust the appliance’s own logs to tell the whole story. I’d validate potential compromise using other telemetry the attacker couldn’t easily manipulate.
Patch affected gateways and check external telemetry for activity attackers may have concealed on the appliance.
Nearly 37,000 Self-Hosted AI Services Face Internet Exposure
Researchers found 36,769 self-hosted AI endpoints reachable from the public internet, including model servers, workflow platforms, and vector stores.
Some of these systems connect to APIs, databases, and cloud services, so compromising one could expose far more than the AI application.
Self-hosting AI doesn’t reduce much risk if the service is publicly reachable and its credentials can open the door to more sensitive systems.
Scan for exposed AI services, restrict public access, and rotate credentials tied to sensitive systems.
OpenAI Agents Tied to Malicious RubyGems Packages
Researchers linked internal OpenAI agents to more than 2,000 RubyGems package submissions and alleged code execution.
OpenAI confirmed its agents accessed RubyGems but has not verified they published the malicious packages, raising questions about accountability for autonomous agent activity.
I think the security question for AI agents is shifting from what they can do to what organizations can prove they did, making attributable identities and detailed activity logs important.
Give AI agents dedicated identities, short-lived credentials, and require human approval for high-risk actions.
Cisco Firewall Flaws Fuel Ransomware Attacks
Attackers are exploiting two Cisco firewall vulnerabilities to steal credentials and configurations, then move deeper into networks.
The activity includes a Sandworm-linked APT and a ransomware operator that ultimately deployed Qilin.
When threat actors compromise the system managing your firewalls, they gain insight into the controls designed to stop them, which can make subsequent attacks harder to detect.
Patch affected FMC systems, hunt for lateral movement, and rotate credentials accessible to the platform.