
Meta founder and CEO Mark Zuckerberg has gone to great lengths to hype the security of its new AI assistant Muse, claiming it is “built from the ground up for privacy and security.” A zero-day vulnerability that gives locally run apps and terminal commands complete control of the agent raises serious doubts. Further raising questions, Amazon on Sunday began blocking Muse from its site. Meta introduced Muse a few weeks ago. The assistant “books appointments, fills out forms and handles customer s
Meta's new AI assistant has a serious security flaw that allows any locally installed app or terminal command to gain control of a user's account, despite the company's claims that it was built with privacy and security in mind. The vulnerability works because the assistant was designed to allow any app to change settings including where voice transcription is processed, and attackers can redirect this to their own server to steal the authentication token that grants complete access. The flaw matters because the assistant has extraordinary access to user data and resources, including the ability to make purchases, access email and social media accounts, and control device features like the camera and microphone. A security researcher demonstrated that a simple ClickFix attack, a common social engineering technique, is sufficient to exploit the vulnerability without requiring the device to be already compromised.

As the US and China race to become the dominant power in the AI industry, the countries also appear to be figuring out ways to communicate on national security issues.

OpenAI CEO Sam Altman discusses AI safety, human control, and international cooperation in remarks to the United Nations Security Council.

Paolo Benanti tells WIRED that hysteria over whether godlike AI could destroy humanity is distracting from the need for public debate about how to govern the technology.
Want to go deeper than the news? Explore live, cohort-based AI courses taught by practitioners.
Browse AI courses on Maven