One Extension, Five AI Assistants (09/16/2026)

September 16, 2026
One Extension, Five AI Assistants (09/16/2026)
Key Intel / TL;DR
  • One browser extension can hijack AI assistants across Chrome, Comet, Edge, Opera Neon, and Claude.
  • A separate technique called BragJack turns a browser's own agentic AI against the user.
  • CISA warned that a critical ScreenConnect flaw is now being actively exploited.
  • Google patched a Pixel modem flaw after confirming some owners were hacked in zero-click attacks.
  • An attacker hijacked an AI coding assistant session and spread Shai-Hulud across roughly 100 repositories.

Two separate pieces of research landed today describing the same structural problem from different angles. The assistant sitting inside your browser has permission to read pages, act on them, and speak with your authority, and the extension layer it lives in was never designed to isolate anything from anything.

Top 5 Critical Security Alerts

1. A Single Extension Reaches Five Different AI Assistants

Researchers demonstrated that one malicious browser extension can hijack AI assistants across Chrome, Comet, Edge, Opera Neon, and Claude, which makes the attack portable across the entire category instead of specific to one vendor. An assistant holds context the user has already authenticated into, so hijacking it inherits the session outright and never needs to steal a credential. The extension permission model predates assistants by a decade and grants page access at a granularity that cannot distinguish reading an article from reading a conversation. The Hacker News has the research.

Operator Note: Pull your fleet’s extension inventory and treat any extension with broad page access on a machine that also runs an AI assistant as a combined risk, because that pairing is the one being demonstrated.

2. BragJack Turns the Browser’s Agent Against the User

Separate research describes BragJack, an attack that redirects a browser’s own agentic AI to act against the person operating it. An agent with permission to navigate, click, and submit is an automation surface with your privileges, and subverting it produces actions that carry every authorization you hold. Nothing here requires the user to be deceived, because the deception happens to the agent. Dark Reading has the technique.

3. CISA Confirms Exploitation of the ScreenConnect Flaw

CISA warned that attackers are actively exploiting a critical ConnectWise ScreenConnect vulnerability, three days after the product appeared in the KEV batch we covered on Saturday. Remote support software is a legitimate remote execution channel with an established reason to reach every endpoint, which is what makes a flaw in it worth so much. Anybody running it should verify the version today rather than at the next change window. BleepingComputer has the warning.

Operator Note: If you use a managed service provider, ask which remote support product they use on your estate and what version it is running, because their patch cycle is your exposure.

4. Pixel Owners Were Hacked in Zero-Click Attacks

Google confirmed that some Pixel phone owners were compromised in zero-click attacks and patched a modem flaw showing signs of limited targeted exploitation. Limited and targeted is the vocabulary used when a capability is expensive and pointed at specific people, which describes surveillance work and not ordinary crime. A modem flaw sits below the operating system and reaches the device without anything appearing on screen. TechCrunch has the confirmation and The Hacker News has the patch.

5. A Hijacked Coding Assistant Spread Shai-Hulud to 100 Repositories

An attacker took over an AI coding assistant session and used it to spread the Shai-Hulud worm across approximately 100 repositories. A coding assistant holds repository credentials and commit authority by design, so a hijacked session is an authenticated developer working at machine speed. This is the second month running that Shai-Hulud has found a new propagation route, and each one has been a place developers keep credentials for convenience. The Hacker News has the campaign.

Operator Note: Scope the tokens your coding assistants hold to the repositories they actually need, because a single broadly scoped token is what turns one hijacked session into a hundred commits.

Additional Security Alerts

Active Exploitation

  • WSO2 API Manager is being hit with forged admin tokens: Attackers are attempting a JWT bypass that mints administrator tokens, which defeats authentication rather than guessing past it. The Hacker News
  • The Acronis cPanel backup flaw is now in targeted attacks: Yesterday’s warning has become confirmed exploitation against selected hosts. The Hacker News
  • A WooCommerce plugin flaw is planting PHP web shells: Attackers are exploiting Wholesale Lead Capture to gain persistent access on WordPress sites. The Hacker News
  • KREMLIN banking malware is hijacking Chrome and Edge: The campaign steals credentials and session tokens directly from the browser, which is the third browser-resident story on today’s board. The Hacker News

Policy and Platform

  • CISA is ending its weekly vulnerability bulletin: The agency decided the publication is no longer necessary, removing a summary a lot of small teams used as their weekly triage input. The Register
  • CISA and NIST published guidance on protecting cloud identity tokens: The guidance lands in a month where replayable tokens have appeared in four separate stories. Infosecurity Magazine
  • A Windows 11 update is breaking domain trust: KB5124008 is causing trust relationship failures for some users, which presents as an authentication outage rather than as a patch problem. BleepingComputer

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)