IntelSecurity IncidentRU
HIGHSecurity Incident·priority

Banking malware, PBX RCE, and AI assistant hijacks—are we entering a new cyber escalation cycle?

Intelrift Intelligence Desk·Wednesday, September 16, 2026 at 07:27 PMEurope (with global cyber spillover)3 articles · 2 sourcesLIVE

A banking malware operation active since mid-2025 is using a toolkit called KREMLIN to bypass browser checks and force-install malicious Chrome and Edge extensions. The campaign targets credential theft by harvesting sensitive data, session tokens, and other information that can enable account takeover and fraudulent transactions. The reporting highlights that the malware’s extension-based approach reduces user friction and increases persistence across common consumer browsers. The same day, researchers disclosed a critical Issabel Framework flaw, CVE-2026-89026, with a CVSS v3.1 score of 9.8 and CVSS v4.0 of 9.3, enabling unauthenticated remote OS command execution. In parallel, Forever Security demonstrated that a single “ordinary” browser extension could hijack AI assistants across multiple Chromium-based products, including Chrome’s Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and the Claude extension. Taken together, the cluster points to a shift from isolated malware incidents toward platform-spanning compromise chains that weaponize trust in browsers, extensions, and web-based communications. Banking crime groups benefit because forced extension installation and session-token theft can bypass traditional authentication friction, turning browsers into credential exfiltration endpoints. The Issabel RCE issue matters geopolitically because PBX/UC systems are often integrated into enterprise communications and can be leveraged for espionage, disruption, or downstream access to broader networks. Meanwhile, the AI-assistant hijack proof-of-concept suggests attackers may increasingly target “assistive” interfaces that users treat as safe, thereby scaling social engineering and data harvesting. This combination favors attackers with strong operational security and monetization pathways, while defenders face a widening attack surface across consumer and enterprise software stacks. Market and economic implications are most visible in cybersecurity spending, identity and access management (IAM) tooling, and browser/endpoint security vendors. If forced extension installation and session-token theft become more common, demand for stronger browser hardening, extension vetting, and token protection is likely to rise, supporting sectors such as endpoint detection and response (EDR), security information and event management (SIEM), and zero-trust access. The Issabel RCE flaw can also drive urgent patching and incident-response costs for organizations running open-source unified communications PBX deployments, potentially increasing spend on managed security services and vulnerability management. While the articles do not name specific tickers, the likely “direction” is risk-premium widening for cyber-exposed enterprises and higher near-term volatility in security-related equities and credit risk for firms with weak patch discipline. For commodities and FX, the direct linkage is limited, but elevated cyber risk can indirectly affect insurance pricing for cyber coverage and increase operational disruption costs. Next, defenders should prioritize rapid patching and exposure reduction for Issabel Framework systems affected by CVE-2026-89026, especially where internet-facing deployments exist. For the KREMLIN-driven extension campaign, monitoring should focus on anomalous extension installs, suspicious Chrome/Edge extension IDs, and unexpected token or credential access patterns tied to browser sessions. The AI assistant hijack demonstration raises a new trigger point: any evidence that extension permissions can be abused to control assistant outputs or intercept user interactions across multiple Chromium-based environments. Watch for indicators such as new malicious extension listings, updated malware tooling that improves bypass techniques, and advisories from major browser vendors regarding extension trust and permission boundaries. Escalation risk is highest if attackers chain these vectors—using PBX access to target organizations, then using browser extension mechanisms to steal credentials and tokens, and finally leveraging AI assistant hijacks to accelerate social engineering—so the next 2–6 weeks of patch compliance and threat-actor updates will be decisive.

Geopolitical Implications

  • 01

    Cybercrime and exploitation campaigns are converging on platform trust (browsers, extensions, AI assistants), enabling faster monetization and broader targeting.

  • 02

    Compromise of PBX/UC infrastructure can translate into strategic access for espionage or disruption, increasing the geopolitical sensitivity of “ordinary” enterprise vulnerabilities.

  • 03

    Cross-platform extension abuse suggests regulators and browser vendors may face pressure to tighten extension permission models and vetting, affecting global tech governance.

Key Signals

  • New malicious extension campaigns that bypass browser checks and increase forced-install success rates
  • Rapid growth in observed exploitation of CVE-2026-89026 against internet-facing Issabel Framework instances
  • Browser vendor advisories or policy changes related to extension permissions and AI assistant integrations
  • Telemetry showing session-token theft patterns correlated with extension activity

Topics & Keywords

KREMLIN toolkitChrome extensionsEdge extensionsCVE-2026-89026Issabel Frameworkunauthenticated OS command executionsession tokensAI assistant hijackForever SecurityPBXKREMLIN toolkitChrome extensionsEdge extensionsCVE-2026-89026Issabel Frameworkunauthenticated OS command executionsession tokensAI assistant hijackForever SecurityPBX

Market Impact Analysis

Premium Intelligence

Create a free account to unlock detailed analysis

AI Threat Assessment

Premium Intelligence

Create a free account to unlock detailed analysis

Event Timeline

Premium Intelligence

Create a free account to unlock detailed analysis

Related Intelligence

Full Access

Unlock Full Intelligence Access

Real-time alerts, detailed threat assessments, entity networks, market correlations, AI briefings, and interactive maps.