Tech News
← Home  ·  All topics

Zero-Day

34 GoKawiil briefs on this topic

Meta patches zero-day flaw in Muse AI agent after 500,000 downloads

Security researcher Patrick Wardle disclosed a zero-day vulnerability in Meta's Muse AI agent that could let attackers redirect users' voice dictations and access tokens to a malicious server instead of Meta's own. David Singleton, head of Meta's Superintelligence Labs, confirmed the company has issued a patch, though he and Wardle disagree on whether the exploit requires prior malware on a user's machine. Meta says the MacOS Muse app has been downloaded over half a million times in its first week.

Meta's Muse AI Assistant Launched With Zero-Day Flaw Exposing Auth Tokens

Security researchers found a zero-day vulnerability in Meta's newly released Muse AI assistant for macOS that lets any locally installed app or terminal command access the token authenticating a user's Muse account, along with a long list of undocumented settings. Amazon has begun blocking Muse on its site, and the flaw undermines macOS permission protections that Apple built to prevent unauthorized apps from reaching sensitive resources like the microphone, camera, and file system.

Arista fixes actively exploited VeloCloud Orchestrator zero-day, CISA sets Sept 25 deadline

Arista Networks has issued patches for CVE-2026-93952, a maximum-severity flaw in on-premises deployments of VeloCloud Orchestrator, the centralized management platform for VeloCloud SD-WANs. The bug, an improper input validation issue affecting setups using certificate-based authentication between edge devices and the orchestrator, lets remote attackers gain privileged internal access without credentials or user interaction, and Arista says it is already being exploited in the wild.

F5 fixes actively exploited BIG-IP APM zero-day, CVE-2026-94127

F5 issued patches for a critical zero-day in its BIG-IP Access Policy Manager, tracked as CVE-2026-94127, which is being exploited to achieve remote code execution on systems configured as an OAuth Authorization Server. F5 says setups using APM only as an OAuth Client or Resource Server are unaffected, and offered an iRule-based mitigation for those unable to patch immediately. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and directed federal agencies to remediate it by Friday.

Meta fixes critical zero-day flaw in Muse AI assistant

Meta has patched a serious security vulnerability found in its Muse AI assistant. The flaw could have let attackers seize control of Muse and exploit its permissions to access a user's connected apps and devices.

ShinyHunters claims new PeopleSoft zero-day used to breach FBI systems

The ShinyHunters extortion group told BleepingComputer it exploited a new remote-code-execution flaw in Oracle PeopleSoft to access FBI systems and move into FBI-managed AWS GovCloud infrastructure, claiming theft of 2-3TB of data including employee, applicant, HR and Medlink records. The group shared a screenshot showing the FBI Jobs site defaced with its logo and a message asserting sensitive PII/PHI had been stolen, and said the FBI quickly took the affected systems offline.

Meta's Muse AI agent for Mac had a 0-day letting any local app redirect voice data

Security researcher Patrick Wardle discovered that any app or Terminal command running on a Mac could silently alter undocumented settings in Meta's new Muse AI agent without requiring special macOS permissions. One affected setting, endo_voyager_dictation_endpoint, determines where a user's dictated voice prompts are transmitted, meaning an attacker could reroute that data elsewhere. The flaw surfaced just weeks after Meta heavily promoted Muse's security architecture, including a dedicated Secure VM, a monitoring system called Sentinel, and bug bounties up to $300,000.

Check Point patches actively exploited zero-day in Security Management Server

Check Point Software has issued emergency hotfixes for CVE-2026-93616, a critical path traversal vulnerability in its Security Management Server that lets unauthenticated attackers upload and run arbitrary scripts. The company confirmed the flaw is being actively exploited, with a handful of customers already compromised, and released a fix in R82.20 Security Hotfix covering Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.

D-Link finds no fix for critical DIR-822A router flaw with public exploit code

D-Link disclosed a maximum-severity vulnerability, CVE-2026-86296, affecting its legacy DIR-822A dual-band routers, caused by a stack-based buffer overflow in the DHCP server component. The bug requires no authentication and can be triggered by sending crafted DHCP packets over the local network, potentially crashing the device or enabling remote code execution. A proof-of-concept exploit is already public, and D-Link has not yet released a patch. The company is also probing a second flaw, CVE-2026-86510, an out-of-bounds write in the L2TP parser reported by the same researcher.

Meta fixes zero-day flaw in Muse macOS app after researcher hijacks AI agent

Security researcher Patrick Wardle found an unpatched setting in Meta's Muse macOS app that let local attackers reroute the app's cloud-based dictation to their own server, effectively seizing control of the AI agent. Wardle demonstrated the flaw by using Muse's own privileges to snap photos and write files to disk, often without alerting the user. Meta issued a hotfix within hours of the report, though it maintains the exploit required existing local access and posed low real-world risk.

Researcher Naceri releases 'BigDiskBuster' zero-day blocking Windows Defender updates

Security researcher Abdelhamid Naceri published a new proof-of-concept exploit called BigDiskBuster that, when run in the background, prevents Microsoft Defender from installing platform or signature updates on any supported Windows version. Naceri describes it as similar to his earlier UnDefend exploit, and says the code is still buggy but demonstrates the concept clearly. This is the latest in a string of nearly a dozen Defender and Windows-related exploits he has released since April 2026 amid an ongoing dispute with Microsoft over his termination.

Meta's Muse AI assistant found to have zero-day flaw exposing user auth tokens

Security researchers discovered that Meta's new macOS AI assistant Muse contains a vulnerability allowing any locally installed app or terminal command to access the authentication token tied to a user's Muse account, bypassing Apple's built-in permission protections. The flaw also lets outside processes alter numerous undocumented settings, some of which could grant deeper control over connected accounts like WhatsApp, email and calendars. Separately, Amazon has begun blocking Muse from its platform.