Zero-Day Attacks Hit Cisco ISE, Google Pixel Modems and AI‑Powered Browsers
A severe flaw in Cisco's Identity Services Engine (ISE) that permits unauthenticated remote code execution is now being actively weaponized, security teams report, while a distinct vulnerability in the modem firmware of Google Pixel smartphones is also being exploited in the wild.
Rated at the highest severity, the Cisco bug strikes the central authentication platform enterprises rely on to enforce network‑access policies. Threat actors have been observed leveraging the defect to establish privileged footholds inside corporate networks, prompting urgent advisories from Cisco and a call for immediate patching. Although the vendor has issued a software update, the swift uptake of the exploit highlights the difficulty of protecting legacy networking gear.
At the same time, a zero‑day in the Android baseband of Pixel devices lets attackers run arbitrary code via specially crafted cellular signals. Because the weakness resides in the modem firmware, it skirts the usual Android security layers by operating beneath the operating system. Google has published a security bulletin and is rolling out fixes, yet the exploit’s active use means many users will stay vulnerable until updates reach every carrier and handset.
Security researchers have also identified a browser‑extension attack named "BragJack" that hijacks AI agents embedded in five major browsers. The rogue extension captures prompts sent to generative‑AI services and redirects them to attacker‑controlled servers. By altering the AI’s replies, the method can siphon data or inject misinformation without the user noticing, underscoring new risks as AI assistants become woven into everyday browsing tools.
In a separate effort, a research team showcased the offensive potential of Anthropic's Claude Opus 5 model by using it to breach OpenAI's systems. By prompting Claude to produce code snippets and exploit scripts, the team managed to slip past certain defensive controls, demonstrating how sophisticated language models can be repurposed for malicious ends. The results have spurred calls for tighter usage policies and improved monitoring of AI‑generated content in security‑critical environments.
These events arrive amid a broader wave of high‑impact flaws, with more than twenty notable security stories reported this week. Experts caution that the convergence of network, mobile and AI attack vectors demands coordinated defensive strategies, faster patch deployment, and heightened awareness among both IT professionals and end users.
Organizations are advised to prioritize the Cisco ISE and Pixel modem patches, scrutinize browser extensions for unusual permissions, and institute robust monitoring of AI interactions. As adversaries continue to exploit zero‑day weaknesses and AI capabilities, the cybersecurity community stresses proactive steps to limit damage before widespread compromise occurs.
Comments (0)
Be the first to comment.
Join the discussion