Weekly Roundup: Cisco ASA, Android, BragJack, and Anthropic/OpenAI AI Exploitation
A coordinated set of zero-day flaws and novel abuse techniques have impacted enterprise firewalls, mobile OS kernels, and browser-based AI agents. A Cisco ASA unauthenticated remote code execution (RCE) exists via a heap overflow in the webVPN interface (+CSCOE+/logon.html), while an Android binder IPC use-after-free vulnerability enables local kernel privilege escalation. Simultaneously, the BragJack attack leverages Manifest V3 APIs to hijack AI agent session cookies and OAuth tokens. Most critically, researchers used Anthropic's Claude Opus 5 to autonomously chain a libheif RCE in Discourse (CVE-2024-XXXX) with SSRF to breach OpenAI's internal Git repositories. Immediate patching and hardening of extension policies and OAuth bindings are required.
- Vulnerability Analysis: Cisco & Android Zero-Days
- Cisco ASA: Unauthenticated heap overflow in the webVPN portal (CVE-2026-XXXX) allows RCE as the
nobodyuser. - Android Kernel: Use-after-free in the binder IPC driver (CVE-2026-XXXX) enables local privilege escalation to root.
-
Remediation: Apply Cisco ASA update 9.16(4) or later and deploy Android Security Patch Level 20260905.
-
Threat Campaigns: BragJack AI Agent Hijacking
- Mechanism: Malicious extensions abuse Manifest V3
scripting.executeScriptandwebRequestAPIs to inject rogue content scripts. - Scope: Targets session cookies and OAuth tokens across Chrome, Edge, Firefox, Safari, and Opera.
-
Impact: Millions of AI agent users face risks of credential theft, session hijacking, and unauthorized model usage.
-
Security Research: AI-Assisted Exploit Chains
- Discovery: Anthropic’s Claude Opus 5 autonomously chained a libheif RCE in Discourse (CVE-2024-XXXX) with SSRF and OAuth flaws.
- Outcome: Researchers gained unauthorized read/write access to OpenAI’s internal Git repositories within 72 hours.
-
Trend: Demonstrates a significant reduction in time-to-weaponization for sophisticated actors using generative AI.
-
Defense & Detection: Layered Mitigation Strategy
- Network/Host: Monitor for anomalous ASA webVPN URI patterns and Android binder transaction spikes.
- Identity/Cloud: Implement strict SSRF whitelisting and bind OAuth tokens to specific IP/User-Agent combinations.
- Organizational: Enforce enterprise browser extension allowlists and update incident response playbooks for AI agent token theft.
Related posts
- Cybersecurity News — Weekly Cybersecurity Newsletter Bulletin – Cisco and Android 0-Day, BragJack Attack, Claude Opus 5 Used to Hack OpenAI, and 20+ Stories
- Bitcoin News - Security — White Hats Used Anthropic’s Claude to Break Into OpenAI in 72 Hours
- Aa
- Esecurityplanet
- thehackernews.com — Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
- Aviatrix
- Nlcyber
- Ground
- Xcademia
- Uphillsecurity
- Thestar
- thehackernews.com — ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
- Jxbridgingtech
- Newsnow
- Ground