Canadian Cyber Security Journal
SOCIAL:
Filed under: News

Cybersecurity Daily Brief — Wednesday, September 16, 2026

Here are today’s top cybersecurity stories for Wednesday, September 16, 2026.

Google Patches Actively Exploited Zero-Day in Pixel Modems
Google released its September 2026 security updates for Pixel devices, fixing 110 vulnerabilities including a modem flaw under limited, targeted exploitation. CVE-2026-58704 stems from a permission bypass in the cellular modem subcomponent, letting an attacker within radio proximity escalate privileges without user interaction. The flaw affects Pixel 6 through Pixel 11 series along with Pixel Tablet and Fold models, all covered by the September 5 patch level. BleepingComputer

New Attack Technique Hijacks AI Assistants Across Five Major Browsers
Researcher Gal Weizman of Forever Security disclosed BragJack, a technique letting a malicious browser extension seize control of the built-in AI agent in Chrome with Gemini, Microsoft Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. The underlying flaw lets an extension send prompts directly to the privileged AI agent, and in some browsers read local files or activate the camera and microphone without a user click. Google and Microsoft assigned CVE-2026-0628 and CVE-2026-55945 respectively, and all five vendors have patched the issue. Dark Reading

New Phishing Kit Defeats MFA Through Device-Code Authentication
Researchers at ANY.RUN detailed N0va, a phishing kit targeting organizations across North America and Europe in government, technology, consulting, and healthcare sectors. The kit impersonates Microsoft Teams, SharePoint, DocuSign, and other trusted platforms, guiding victims through legitimate device-code authentication flows to capture access and refresh tokens surviving multi-factor authentication and password resets. Stolen tokens let attackers establish single sign-on access to email, files, and cloud applications. The Hacker News

Suspected North Korean Group Targets South Korean Media and Automotive Firms
Rapid7 attributed a Linux-based espionage campaign against South Korean media and automotive companies to a suspected North Korean threat group, with medium confidence based on command-and-control infrastructure overlapping known APT37 activity. The attackers trojanized a HAProxy load balancer build and modified system binaries including crond, agetty, and sshd to enable remote command execution and credential harvesting while blending into normal traffic. Some intrusions have persisted since early 2025. Dark Reading

Spain Logs First Data Breach Attributed to an Autonomous AI Agent
Spain’s data protection authority, the AEPD, received its first breach notification describing an AI agent as the tool used to carry out an attack with limited human involvement at each stage. The affected organization reported the agent used a widely available large language model to identify a vulnerability, gain system access, and modify personal data and invoices. The AEPD has not named the model, its provider, or the targeted organization, and says its review continues. BleepingComputer

New Malware-as-a-Service Platform Rents Full Windows Attack Toolkit for $250 a Month
Researchers at SOCRadar identified VectraRAT, a previously undocumented malware-as-a-service platform combining a Windows implant, custom command-and-control infrastructure, and an operator panel, built entirely from scratch rather than forked from existing malware. Delivered through Amadey loaders and ClickFix pages, the tool bypasses Windows User Account Control without triggering an elevation prompt and includes keylogging, credential theft, and proxy functions. SOCRadar found victims concentrated in the United States, Russia, and Germany, with corporate Windows editions accounting for nearly half of infections. Dark Reading

Chrome and Firefox Updates Patch 115 Vulnerabilities
Google released Chrome 153, fixing 42 security defects including three critical use-after-free and out-of-bounds read flaws, while Mozilla shipped Firefox 156 with fixes for 73 vulnerabilities, 29 rated high severity and covering use-after-free, sandbox escape, and privilege escalation issues. Neither vendor reported active exploitation of the patched flaws. SecurityWeek

Microsoft Ships Emergency Fix for the Update Breaking Remote Desktop Services
Microsoft released emergency out-of-band updates to resolve a Remote Desktop Services failure caused by its September 2026 Patch Tuesday cumulative updates on Windows Server 2019, 2022, and 2025. The original updates, released September 8, caused RDS to fail hours after installation, forcing many administrators to roll back the security fixes entirely while awaiting a solution. Microsoft has not detailed the root cause of the regression. BleepingComputer

Compromised HBO Max Reddit Account Spreads Malware in 108 Fake Ads
Researchers at Hudson Rock and ADAMnetworks say attackers hijacked HBO Max’s verified Reddit account and ran 108 malicious advertisements over roughly 48 hours, targeting Windows and macOS users. The ads used the ClickFix technique, tricking victims into pasting attacker-supplied commands into the Windows Run dialog, PowerShell, or macOS Terminal under the guise of fixing an error or verifying a download, split between HBO Max, OpenAI Codex, and fake developer tool lures. Researchers link the campaign to a broader operation dubbed PasteSwitch, and Reddit paused the ads after receiving reports. BleepingComputer

Stay tuned for today’s in-depth analysis posts.

Enjoy this article? Don’t forget to share.