Threat Brief — 2026-09-16 — AI Agents Under Attack
A critical unauthenticated RCE in Issabel Framework (CVE-2026-89026, CVSS 9.8) is under active exploitation, giving attackers OS-level command execution on exposed PBX systems. Three separate AI-related attacks emerged today: a single browser extension can hijack AI assistants across five Chromium-based products, an attacker hijacked an active AI coding-assistant session to spread malware across ~100 repositories, and Spain's data agency received its first formal report of an AI-powered data breach. A Parallels Desktop local privilege-escalation flaw gives non-admin Mac users root, though Intel Macs cannot install the available fix.
Top items
- Issabel Framework unauthenticated RCE actively exploited. CVE-2026-89026 (CVSS v3.1: 9.8) in the web-based framework for open-source unified communications PBX software enables unauthenticated OS command execution. Attackers are already exploiting it in the wild. Any internet-exposed Issabel deployment is at risk of complete compromise. (src: The Hacker News)
- Browser extension can hijack AI assistants across Chrome, Edge, Comet, Opera Neon, and Claude. Researchers at Forever Security demonstrated that a single ordinary browser extension can take control of built-in AI assistants in five Chromium-based products — Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and Claude — to access sensitive information, execute malicious actions, and exfiltrate data. The attack exploits the trust model between browser extensions and integrated AI agents. (src: The Hacker News), (src: Dark Reading)
- Attacker hijacks AI coding-assistant session, spreads Shai-Hulud across ~100 repositories. Mandiant reports an attacker hijacked an active AI coding-assistant session at an unnamed SaaS provider and subsequently spread malware dubbed Shai-Hulud across approximately 100 internal code repositories. This is a concrete demonstration of AI-assisted development tools becoming a lateral-movement vector. (src: The Hacker News)
- Parallels Desktop flaw grants root to non-admin Mac users; Intel Macs left without fix. A vulnerability in a built-in Parallels Desktop service allows an ordinary local account already running code on the machine to escalate to root. JFrog disclosed the flaw this week; the fix is available but cannot be installed on Intel-based Macs, leaving those systems permanently exposed unless Parallels is removed or mitigated otherwise. (src: The Hacker News), (src: SecurityLab)
- Three threat clusters — NightEagle, Hacking Cat, and Toy Ghouls — target Russian enterprises. Kaspersky identified multiple attack campaigns against Russian enterprises deploying backdoors, ransomware, and wipers across these three activity clusters. This expands on the NightEagle APT campaign reported earlier today with its GhostContainer backdoor. (src: The Hacker News)
- Digital Watchdog VMAX DVR and NVR vulnerabilities enable full administrative takeover. CISA published an ICS advisory (ICSA-26-258-01) for vulnerabilities in Digital Watchdog's VMAX product lineups. Successful exploitation grants full administrative control, allowing attackers to view live and recorded surveillance footage, alter configurations, and potentially use devices as persistence footholds. (src: CISA)
- Spain's AEPD receives first formal report of an AI-powered data breach. The Spanish Data Protection Agency was notified of an attack allegedly carried out using an AI agent powered by a known large language model. This is reportedly the first such notification to the agency, marking a regulatory milestone as AI-driven attack tooling enters formal breach-reporting channels. (src: BleepingComputer)
Themes
AI as both weapon and target. Three of today's top stories involve AI systems being weaponised or subverted: a browser extension hijacking agentic AI assistants, a coding-assistant session being commandeered to spread malware, and Spain's first AI-powered breach notification. Organisations deploying AI agents in production-facing roles face a trust-model problem that traditional browser-security controls do not address. Separately, the Parallels and Issabel findings reinforce that unpatched infrastructure software — particularly PBX frameworks and hypervisor services — remains the most direct path to system compromise.
