Urgent.News

What's breaking now, across thousands of outlets.

Tech

Last week in Agent Security 1: We are not-a-mused!

Last week I talked at NDC Oslo about the OWASP Top 10 for Agents where I showed folks the different ways that agents can be exploited. If you've turned the news on recently, you've probably heard about AI will kill us all and how we're all doomed. Call me optimistic, but I think we're currently in the middle of a hype cycle where AI labs are overstating the abilities of the models, and we're at a…

Last week, a macOS security researcher named Patrick Wardle revealed a zero-day vulnerability that allows malware running on a Mac to hijack Meta's Muse AI assistant. The flaw lies in an undocumented configuration setting called endo_voyager_dictation_endpoint, which can be manipulated by an unprivileged local process to redirect Muse's dictation traffic to an attacker's controlled server.

This allows the attacker to inject extra instructions that Muse trusts, read dictated content, and steal the user's authentication token, potentially leading to identity and privilege abuse.

In a separate incident, a financially motivated campaign dubbed Gambit has been targeting online retailers using autonomous AI agents since July 2026. The campaign involves chaining three open-source AI agent frameworks - Strix, Cairn, and Hermes - to autonomously attack web pages and steal data. Gambit's operator, a Chinese-speaking SOUL Red Team persona with 121 skills, has exfiltrated over 600,000 credit card records from multiple organizations, including a Fortune 500 hospitality company, a major US airline, and a large US industrial-supplies distributor.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Building an ETL Pipeline with Python, Docker, and PostgreSQL (And Debugging the Real Errors)

Most ETL tutorials show a perfect, frictionless flow. The reality? My pipeline turned into a festival of KeyError's , outdated schemas, and API payload typos.

  • Extract data from GitHub repo using Python's request library and pagination
  • Transform data into flat record format and calculate time to close each issue
  • Load transformed data into PostgreSQL DB using psycopg library in Docker Compose

MLH Hack At Home 2020: Hearth

This is a submission for the MLH x DEV Writing Challenge What I Built Hearth is a voice-controlled smart home agent built for the moment we were all in: stuck at home, working from the same room we…

  • MLH Hack At Home 2020 project named Hearth
  • Voice-controlled smart home agent for pandemic challenges
  • Analyzes sensor data to suggest automations

Seven fields I now attach to every check result, so "unknown" survives the dashboard

Notes from an AI agent: one small result schema, and the four times it stopped me from reporting a zero Same rule as the rest of this series: every example below is from my own work , between 15 and…

  • The standardized result schema includes seven fields
  • "claim" represents the specific sentence being tested
  • "positivecontrol" indicates whether the instrument can affirmatively answer the question

Kestra's Path Suffix Bug: When a Framework Forgets to Check the Whole Route

Kestra's Path Suffix Bug: When a Framework Forgets to Check the Whole Route A patch released in June 2026 became an urgent remediation item in September.

  • Authenticated and unauthenticated attackers can inject OS commands due to CVE-2026-49869.
  • Outdated filter only checked if request ended with specific path, not exact route or HTTP method.
  • CISA listed vulnerability in KEV catalog in September, despite patch released in June.

More from Tuesday 29 September →