Morning Review in IT Security — September 17, 2026
The threat landscape continues to evolve rapidly as security researchers uncover critical vulnerabilities affecting widely-used platforms and tools. Today's review covers emerging threats to AI assistants, major patching obligations from Oracle, enterprise authentication disruptions, and state-sponsored espionage campaigns targeting vulnerable populations.
Browser Extension Vulnerability Threatens AI Assistants Across Multiple Platforms
Security researchers at Forever Security have discovered a critical vulnerability that allows a single malicious browser extension to hijack AI assistants across five major Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and the Claude in Chrome extension. Once installed, the extension can gain unauthorized access to each product's built-in AI functionality with minimal user interaction. This attack vector represents a significant risk to users who rely on these AI tools for sensitive tasks and information processing. Source: The Hacker News
The vulnerability affects multiple CVE identifiers including CVE-2026-0628 and CVE-2026-55945, along with infrastructure at testing.perplexity.com. Organizations should exercise caution when installing browser extensions and consider implementing strict extension policies within their security frameworks.
Oracle Addresses 673 Vulnerabilities in September Critical Patch Update
Oracle has released its September 2026 Critical Security Patch Update, addressing a substantial number of security vulnerabilities across its product portfolio. The update patches 673 security vulnerabilities in total, with 104 of these classified as critical severity. These vulnerabilities span multiple Oracle product families and include patches for third-party components integrated into Oracle products. Source: Qualys Blog
The critical CVEs addressed include CVE-2026-83154, CVE-2026-83196, CVE-2026-83197, CVE-2026-83201, CVE-2026-83202, CVE-2026-83229, CVE-2026-83327, CVE-2026-83452, and CVE-2026-83462. Organizations running Oracle products should prioritize testing and deployment of these patches to their systems.
Windows 11 Security Update Creates Domain Authentication Issues
Microsoft is investigating reports that the Windows 11 KB5124008 security update is causing domain trust relationship failures on some enterprise systems. The update is preventing users from logging in with valid domain credentials, creating significant disruptions in affected organizations. Source: Bleeping Computer
This issue highlights the critical need for organizations to test security updates in controlled environments before broad deployment. Affected enterprises should monitor their domain authentication systems closely and consider temporary rollback procedures if widespread impact occurs.
Iranian State-Linked Hackers Deploy CHOSEN BRICK Malware Against Dissidents
Government agencies are warning that Iranian state-linked threat actors are actively using a Windows malware strain called CHOSEN BRICK to conduct surveillance operations against dissidents, activists, and journalists worldwide. The malware represents a targeted espionage threat directed at vulnerable populations and individuals at risk. Source: Bleeping Computer
This nation-state campaign underscores the ongoing threat posed by state-sponsored actors targeting high-risk individuals. Organizations supporting journalists, activists, and at-risk populations should implement enhanced endpoint protection and user awareness training focused on social engineering tactics commonly employed in such campaigns.
The convergence of these threats—from browser-based vulnerabilities to critical patch obligations and nation-state operations—emphasizes the importance of maintaining comprehensive security postures across infrastructure, applications, and user awareness programs.