Last week in Agent Security 1: We are not-a-mused!
Last week I talked at NDC Oslo about the OWASP Top 10 for Agents where I showed folks the different ways that agents can be exploited. If you've turned the news on recently, you've probably heard about AI will kill us all and how we're all doomed. Call me optimistic, but I think we're currently in the middle of a hype cycle where AI labs are overstating the abilities of the models, and we're at a…
Last week, a macOS security researcher named Patrick Wardle revealed a zero-day vulnerability that allows malware running on a Mac to hijack Meta's Muse AI assistant. The flaw lies in an undocumented configuration setting called endo_voyager_dictation_endpoint, which can be manipulated by an unprivileged local process to redirect Muse's dictation traffic to an attacker's controlled server.
This allows the attacker to inject extra instructions that Muse trusts, read dictated content, and steal the user's authentication token, potentially leading to identity and privilege abuse.
In a separate incident, a financially motivated campaign dubbed Gambit has been targeting online retailers using autonomous AI agents since July 2026. The campaign involves chaining three open-source AI agent frameworks - Strix, Cairn, and Hermes - to autonomously attack web pages and steal data. Gambit's operator, a Chinese-speaking SOUL Red Team persona with 121 skills, has exfiltrated over 600,000 credit card records from multiple organizations, including a Fortune 500 hospitality company, a major US airline, and a large US industrial-supplies distributor.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.