BragJack attacks hijack AI browser agents through malicious extensions

2026-09-19T19:23:20Z•fe94afc2824ddbaf360ee7624df0191d37c7affa26921c78f3b6064102bd3e79
AI-agent securityAndroid malwareCheck PointClickFixGyazoMicrosoft 365Microsoft TeamsNorth KoreaRapuncelRatHatWaterPlumcryptocurrency theftdata breachinfostealermalicious browser extensionsprompt injectionransomwareremote code executionroot privilegessupply-chain attack

What happened

A BleepingComputer security-news feed covering active threats, vulnerabilities, data breaches, malware campaigns, supply-chain compromise, and AI-agent security issues. Notable items include the BragJack proof-of-concept that hijacks AI browser agents via malicious extensions and reportedly resulted in two CVEs, the WaterPlum North Korean campaign compromising at least 30,000 devices and stealing over $10.7 million in cryptocurrency, a Gyazo breach affecting 23.6 million records, a critical Check Point flaw enabling root-level code execution, the Rapuncel infostealer campaign, RatHat Android/R

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
fe94afc2824ddbaf360ee7624df0191d37c7affa26921c78f3b6064102bd3e79
Enrichment time
2026-09-19T19:23:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.