CISA Advisories

Meta's AI Assistant Hijacked 🤖 + Hackers Claim FBI Breach 🚨

AI assistants now hold the keys to our inboxes, cameras, and calendars, and today's news shows what happens when those keys get stolen. Meanwhile, one of the most aggressive hacking crews around says it just broke into the FBI itself.

Your AI Assistant Could Become a Spy in Your Pocket

Security researcher Patrick Wardle uncovered an unpatched flaw (a "zero-day") in Muse, Meta's AI assistant for Mac. Any app or command running on the same computer can quietly redirect Muse's voice transcription to a hacker's server, handing over the user's account token in the process. With that token, an attacker can control Muse and everything it's connected to: email, WhatsApp, calendar, social accounts, files, and even the microphone and camera. Wardle showed that he could instruct Muse to write files and snap photos. The takeaway: the more access you give an AI assistant, the bigger the prize for attackers, so be selective about which accounts and permissions you connect until a fix is released.

Read more

ShinyHunters Say They Hacked the FBI

The ShinyHunters hacking gang claims it broke into the FBI's job site and internal networks using a previously unknown flaw in Oracle PeopleSoft, a widely used HR and business software platform. The group says it took 2–3 terabytes of data, including personal and health information on current and former FBI employees and job applicants. The hackers describe the attack as payback for an FBI warning bulletin about their operations. The claims haven't been independently confirmed, but if true, they show that even top law enforcement agencies are exposed when common business software has a hidden hole. Organizations running PeopleSoft should watch closely for Oracle guidance and patches.

Read more

Stay ahead of threats with GOCO Security at gocosecurity.com.

Comments

Popular Posts