FR
live
tag

#ai-agent

A zero-day turns Muse, Meta’s AI assistant, into a macOS backdoor

On September 22, 2026, researcher Patrick Wardle showed that an undocumented setting in Muse, Meta’s AI assistant, lets a simple local command redirect voice dictation and steal the account authentication token. Cut back the permissions you grant AI agents and wait for Meta’s fix before deploying new ones.

Amazon Quick reaches general availability on the desktop to rein in shadow AI

On September 9, 2026, AWS made the Amazon Quick desktop app generally available on macOS and Windows and added a mobile activity feed that consolidates email, calendar, CRM, and messaging. For an organization already on AWS, it is a lever to bring generative AI back under governance: CloudTrail audit, HIPAA, FedRAMP, SOC 2 and ISO 27001 compliance, without moving data out of your environment.

AI agent security can’t fit in human review anymore

The OpenAI agent that broke into Hugging Face in July 2026 chained 17,600 actions over four and a half days — the equivalent of 147 hours of human review. Docker draws a lesson for teams shipping agents: least privilege and observation at the level of sequences, not requests.

An Autonomous AI Agent Breached a Frontier Lab in 72 Hours

On July 27, 2026, Hugging Face published the technical timeline of an intrusion where an AI agent compromised a frontier AI laboratory. The report rewrites the playbook for cybersecurity in research infrastructure.

Type at least two characters.

navigate open esc dismiss