{
  "id": 10566866,
  "title": "Last week in Agent Security 1: We are not-a-mused!",
  "url": "https://urgent.news/2026/09/29/last-week-in-agent-security-1-we-are-not-a-mused",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-29T00:15:01.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/willvelida/last-week-in-agent-security-1-we-are-not-a-mused-dm7"
  },
  "original_language": "en",
  "account": "Last week, a macOS security researcher named Patrick Wardle revealed a zero-day vulnerability that allows malware running on a Mac to hijack Meta's Muse AI assistant. The flaw lies in an undocumented configuration setting called endo_voyager_dictation_endpoint, which can be manipulated by an unprivileged local process to redirect Muse's dictation traffic to an attacker's controlled server. This allows the attacker to inject extra instructions that Muse trusts, read dictated content, and steal the user's authentication token, potentially leading to identity and privilege abuse.\n\nIn a separate incident, a financially motivated campaign dubbed Gambit has been targeting online retailers using autonomous AI agents since July 2026. The campaign involves chaining three open-source AI agent frameworks - Strix, Cairn, and Hermes - to autonomously attack web pages and steal data. Gambit's operator, a Chinese-speaking SOUL Red Team persona with 121 skills, has exfiltrated over 600,000 credit card records from multiple organizations, including a Fortune 500 hospitality company, a major US airline, and a large US industrial-supplies distributor.",
  "summary": "Last week I talked at NDC Oslo about the OWASP Top 10 for Agents where I showed folks the different ways that agents can be exploited. If you've turned the news on recently, you've probably heard about AI will kill us all and how we're all doomed. Call me optimistic, but I think we're currently in the middle of a hype cycle where AI labs are overstating the abilities of the models, and we're at a…",
  "key_points": [
    "macOS zero-day vulnerability allows malware to hijack Meta's Muse AI",
    "Gambit campaign targets online retailers with AI agents since July 2026",
    "Gambit operator steals 600K+ credit card records from Fortune 500 companies"
  ],
  "editors_take": "This development highlights the vulnerability of AI assistants and online retailers to exploitation by malicious actors, allowing them to steal sensitive user data and gain unauthorized access.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}