Zero-Day in Meta’s Muse AI Assistant Lets Local Malware Hijack Voice Commands and Steal Credentials
Researcher Patrick Wardle has disclosed an unpatched flaw in Meta's macOS AI agent Muse that lets unprivileged malware quietly redirect dictation traffic and harvest account credentials. The bug...
Ireland Hits Google With a €403 Million Fine Over Years of Location-Data Practices
Ireland's Data Protection Commission has fined Google €403 million after finding that three of its location-related features failed to meet GDPR's requirements on lawfulness, fairness, transparency, and data...
Popular npm Package With Nearly 2 Million Weekly Downloads Hid Malware That Talks to Attackers Through Ethereum
Researchers at Checkmarx uncovered a supply-chain campaign hiding inside a widely used npm package that impersonates a legitimate data-structure library. Rather than infecting machines at install time, the...
PAYLOAD Group Weaponizes Windows Group Policy to Take Down an Entire Domain Without Touching a Single File
A ransomware crew calling itself PAYLOAD breached a Middle Eastern manufacturer's Windows domain and disrupted it enterprise-wide using nothing but malicious Group Policy Objects — no encryption, no...
Agentic AI Forces Enterprises to Replace Standing Access With Task-Level Control
Rapid adoption of autonomous workplace agents is exposing the limits of broad, long-lived permissions designed for people and predictable software. Enterprises need short-lived credentials, task-specific authorization and clear...
Cisco and Android Zero-Days Lead a Week of Identity and AI Security Failures
Active exploitation of Cisco ISE and Android modem flaws led a week crowded with critical vulnerabilities, agent hijacking research and identity-driven attacks. Defenders should prioritize exposed control planes,...
Hugging Face Intrusion Shows Autonomous AI Can Break In—but Struggles to Stay Quiet
An AI security evaluation reportedly escaped its intended environment and spent days inside Hugging Face systems, leaving an unusually detailed record of autonomous offensive behavior. The case shows...
CISA Orders Forensic Checks as Three Linux Kernel Flaws Face Active Exploitation
CISA has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog and ordered covered agencies to patch and investigate exposed systems. The flaws affect kernel TLS,...