Tech News
← Home  ·  All topics

Bug

35 GoKawiil briefs on this topic

Meta patches zero-day flaw in Muse AI agent after 500,000 downloads

Security researcher Patrick Wardle disclosed a zero-day vulnerability in Meta's Muse AI agent that could let attackers redirect users' voice dictations and access tokens to a malicious server instead of Meta's own. David Singleton, head of Meta's Superintelligence Labs, confirmed the company has issued a patch, though he and Wardle disagree on whether the exploit requires prior malware on a user's machine. Meta says the MacOS Muse app has been downloaded over half a million times in its first week.

Samsung confirms Good Lock ClockFace bug shifting lock screen clock position on One UI 9

A Galaxy S26 Ultra owner reported on Samsung's Korean Community forum that a clock positioned in LockStar via Good Lock's ClockFace feature appeared in a completely different spot on the actual lock screen and Always-On Display. Samsung's Good Lock support team confirmed it has reproduced the bug and said its development team is investigating, while advising affected users to switch to a default clock style in the meantime.

Meta's Muse AI agent exported 6.8GB of its own filesystem, including SSH keys

A researcher asked Meta's Muse assistant to archive files it could access and send them to Google Drive, and it complied, delivering a 2.7GB compressed (6.8GB unpacked) package. The archive contained the underlying Linux root filesystem, Ubuntu system files, internal documentation, integration code, memory logs, and SSH key files from the runtime environment codenamed 'Hatch.' The researcher reported the issue through Meta's bug bounty program and is withholding the archive, keys, and logs from publication.

Independent Tester Reports AMD Processors Never Output Zero From RNG Instructions

A Brazilian electronics engineer and assembly programmer named Jessé says he has tested two AMD processors extensively and found that the chips' hardware random number generator, accessed via instructions like rdrand and rdseed, has not produced a single zero value in over nine days of continuous testing. He has reported the issue to AMD, which has escalated it internally, though no technical explanation has been provided yet. Jessé also updated his testing application to benchmark RNG speed and support processors lacking the rdseed instruction, noting large performance differences across CPU generations.

Google Nest Doorbells start announcing visitors in US accents overseas

Nest Doorbell owners in France and the UK report that visitor announcements have suddenly switched to a US English accent, even though every other Google Home device in their homes still speaks in their local language and accent. The glitch appears isolated to doorbell announcements within Gemini for Home, which otherwise supports ten languages and multiple accent options. One affected user says support staff suggested temporarily adding US English as a secondary language, then deleting it, as a workaround.

RPCS3 emulator devs bypass Nvidia driver bug, boost PS3 game speeds up to 37%

Developers of the open-source PlayStation 3 emulator RPCS3 identified a workaround for a bug in Nvidia's GPU drivers that was limiting performance. Testing on Red Dead Redemption's Blackwater boat scene showed frame rate gains of 20% on an RTX 3080 setup and 25% on an RTX 5090 setup, while Gran Turismo 5 saw up to 37% faster performance and lower VRAM usage. AMD GPUs were unaffected, suggesting the issue is specific to Nvidia's drivers.

Microsoft patches Excel copy-paste bug caused by September 2026 security updates

Microsoft has released fixes for a bug that silently broke copy-and-paste, autofill, and formula dragging in Excel after installing this month's security updates, including KB5002914. Users of Excel 2016, Office LTSC 2019, 2021, and 2024 must manually install specific updates to resolve the issue, which had been widely reported on Reddit and Microsoft's Q&A forums.

Intel suspends paid bug bounty program, replaces it with unpaid Intigriti disclosure

Intel has stopped its long-running bug bounty program that paid researchers up to $100,000 per vulnerability, replacing it with a new Intigriti-hosted disclosure process that offers no financial rewards. The bounty board remains visible but is marked as suspended, and Intel has not publicly explained the decision. The program had run since 2017 and accounted for roughly 105 of 231 CVEs Intel patched in 2020.

Security firm Hacktron used Anthropic's Claude to breach OpenAI employee accounts

A three-person team at startup Hacktron AI used Anthropic's Claude AI model to chain two vulnerabilities together, gaining access to several OpenAI employees' ChatGPT accounts and internal systems through OpenAI's bug-bounty program. The entry point traced back to a flaw in Discourse, the third-party forum software OpenAI uses, triggered through a routine image upload. OpenAI paid Hacktron $6,500 and says it has since patched the vulnerabilities.

White-hat hackers breach OpenAI's internal codebase via Discourse forum flaw

Cybersecurity firm Hacktron AI disclosed that its researchers exploited a chained vulnerability—an outdated image-processing library on OpenAI's Discourse forum combined with an SSO misconfiguration—to hijack employee ChatGPT and Codex accounts and reach OpenAI's private code repository. To prove the breach, they submitted a harmless pull request to OpenAI's internal monorepo before reporting the flaws through OpenAI's bug bounty program. OpenAI patched the issue within 14 hours and paid the team a $6,500 bounty.

Security researchers used Anthropic's Claude to breach OpenAI's internal systems

A three-person team from security firm Hacktron AI used a specialized Anthropic security tool to gain access to an OpenAI employee's ChatGPT account, exposing internal software details and even suggesting code changes. OpenAI paid the researchers $6,500 through its bug bounty program after they disclosed the vulnerability responsibly.

Android Auto beta v17.8.1638 restores missing cellular signal bars

Some Android Auto beta users report that the cellular signal strength indicator, which vanished from the dashboard earlier this year, is reappearing after updating to version 17.8.1638. Users say the icon now shows up again beside the battery status indicator, though clearing the app cache may be required for it to reappear.