Spots

Last week in Agent Security 1: We are not-a-mused!

Last week I talked at NDC Oslo about the OWASP Top 10 for Agents where I showed folks the different ways that agents can be exploited. If you've turned the news on recently, you've probably heard about AI will kill us all and how we're all doomed.

Call me optimistic, but I think we're currently

Call me optimistic, but I think we're currently in the middle of a hype cycle where AI labs are overstating the abilities of the models, and we're at a point where we've seen how powerful agents can be, but we need to be more serious about the harms agents can do, and how we can mitigate those risks.

With that in mind, I'll aiming to do

With that in mind, I'll aiming to do a weekly blog post on different agentic attacks and incidents, what happened, how it happened, and what OWASP risks they fall under. Depending on demand or the severity/publicity of the attack, I may do a deep dive on how you could prevent such an attack in the first place.

I'll point out that I'm not trying to

I'll point out that I'm not trying to shame any of the companies involved, nor do I condone any of the methods used in any of these incidents. My goal here is just to spread awareness of the different ways that agents can be exploited, and hopefully trigger a conversation with your teams on how you should protect your agents and the people who use them from potential vulnerabilities. Here's some incidents that have happened over the period 21st-27th September 2026. Meta Muse macOS zero-day ("not-a-mused")

On September 21st 2026, macOS security researcher Patrick

On September 21st 2026, macOS security researcher Patrick Wardle (also founder of the Objective-See Foundation) created a POC (amusingly called "not-a-mused") showing that malware already running inside a Mac can hijack Meta's Muse AI assistant.

The flaw centers on a undocumented configuration setting

The flaw centers on a undocumented configuration setting endo_voyager_dictation_endpoint that an unpriviledged local process can flip to reroute Muse's dictation traffic to an attacker's controlled server (via your own microphone). From there, you could inject extra instructions that Muse trusts, read dictated content from Muse, and steal the authentication token that signs into the user's Muse account. You can use Muse on multiple devices, which extends the blast radius.

Meta have apparently released a hotfix, but we

Meta have apparently released a hotfix, but we see a number of risks being highlighted here. Theft and reuse of the agent's token (Identity & Privilege Abuse), injected goal hijack of the instructions that the agent acts on (Agent Goal Hijack), and how a trusted assistant becomes an attack surface (Human-Agent Trust Exploitation). Gambit "Strix/Cairn/Hermes" autonomous card-skimming campaign

Gambit Security published an interim report about a

Gambit Security published an interim report about a financially motivated campaign in which a single operator chained three open-source AI agent frameworks to attack online retailers autonomously. They've traced the attack to July 2026 and it's still ongoing (at time of writing).

The first framework involved is Strix, which is

The first framework involved is Strix, which is an open source AI penetration testing tool. Between 23rd and 31st August, Strix was run in deep mode against various hosts to provide reconnaissance and vulnerability discovery.

Cairn, which is an automated penetration testing engine

Cairn, which is an automated penetration testing engine, was then used to launch attacks. Each attack path was chosen by the harness in real time through extensive probing and exploitation attempts, resulting in dynamic and mostly different TTPs across victims.

News

Last week in Agent Security 1: We are not-a-mused!

Last week I talked at NDC Oslo about the OWASP Top 10 for Agents where I showed folks the different ways that agents can be exploited.

@spots #dev
Source: Dev.to
See more like this