Feed aggregator
Malicious B-tree NPM Package Accumulates Millions of Downloads
Posing as the legitimate sorted-btree package, indexed-btree hides a malware trigger in its prototype method.
The post Malicious B-tree NPM Package Accumulates Millions of Downloads appeared first on SecurityWeek.
‘Sovereign AI’ is everywhere but rarely defined. It bundles ownership, control, jurisdiction, capability and optionality. The real test for most organisations is, do you know your dependencies, and can you leave if you need to?
The British Medical Association (BMA) has written to MP committees calling for the Capita-run GP pension scheme to be brought in-house
Meta’s Muse AI assistant has a zero-day that can turn it into a Mac backdoor
Mac security researcher Patrick Wardle says it’s trivial to turn Muse into “the ultimate backdoor.”
Increasingly, AI assistants are changing from tools that simply answer questions into agents that can plan tasks, use connected services, and take actions for us. These actions might include booking appointments, filling out forms, creating documents, making purchases, or interacting with email and calendars.
To do that, they need more permissions, account connections, and sensitive data. So, when Meta promised that “Muse is built from the ground up for privacy and security,” we did not expect an AI agent that can easily be manipulated into handing all that access to an attacker.
Meta says Muse can handle appointments, forms, customer-service interactions, purchases, document creation, and connections to services such as WhatsApp, email, calendars, and social platforms. It may also receive macOS permissions to access protected resources, including files, the microphone, camera, location, and calendars.
According to Ars Technica, Wardle found that a locally running application or terminal command could alter an undocumented Muse configuration setting that controls the server used for dictation transcription. By redirecting dictation traffic to an attacker-controlled server, an attacker could capture voice prompts and obtain the authentication token for the victim’s Muse account.
This is not a remote-code-execution vulnerability that can compromise an otherwise clean Mac. The attacker first needs a way to run code locally, such as through malware, a malicious application, or social engineering.
But as we have seen with infostealer malware finding its way onto Macs, that initial access is far from impossible.
Someone’s watching your accounts. Make sure it’s us.Traditional infostealer malware must independently locate browser data, credentials, documents, chat histories, and other valuable material. A compromised AI agent could lower that barrier by bundling access to multiple services and operating-system permissions behind one already authenticated interface.
Ultimately, this is not just about one unsafe configuration setting. It shows why AI agents need a higher security standard than ordinary apps.
How to stay safeWardle’s advice about Muse is simple: “Please don’t install.”
The same caution should apply to other AI agents.
The Open Worldwide Application Security Project (OWASP), a nonprofit foundation that provides free application-security guidance, lists prompt injection, tool abuse, privilege escalation, data exfiltration, excessive autonomy, memory poisoning, and sensitive-data exposure among the major security risks posed by AI agents.
A useful rule is that an AI agent should not have more access than it needs, and it should not be able to turn untrusted instructions into sensitive actions without meaningful checks. In practice, this means:
- Avoid giving a new agent broad access to email, chat apps, calendars, cloud storage, payment methods, and device permissions all at once.
- Regularly review and remove connections the agent does not genuinely need.
- Be aware of prompt injection. Do not assume that an AI agent will recognize malicious instructions embedded in a webpage, document, email, or other external content.
- Watch for unusual agent behavior, such as unexpected requests for new permissions, account reauthentication, external file sharing, or actions you did not initiate.
You should also protect your device against malware:
- Keep your software updated so attackers can’t use known vulnerabilities against you.
- Use an up-to-date, real-time anti-malware solution on all your devices.
- To protect against ClickFix attacks, don’t follow instructions you find on websites and in unsolicited messages that tell you to run commands.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
WordPress Patches ‘Click2Shell’ Vulnerability
The bug lets attackers automatically install and preview themes and could lead to remote code execution.
The post WordPress Patches ‘Click2Shell’ Vulnerability appeared first on SecurityWeek.
A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight
Saudi Arabia wants a car industry, launches Ceer with two EVs
Article URL: https://arstechnica.com/cars/2026/09/saudi-arabia-wants-a-car-industry-launches-ceer-with-two-evs/
Comments URL: https://news.ycombinator.com/item?id=49798754
Points: 1
# Comments: 0
Six ways to integrate Jev into your application
Article URL: https://vercel.com/i/jev-integrations
Comments URL: https://news.ycombinator.com/item?id=49798738
Points: 1
# Comments: 0
TypeSafe AI Jev vs. GPT-6 Astra
Article URL: https://vercel.com/i/jev-vs-gpt-6-astra
Comments URL: https://news.ycombinator.com/item?id=49798734
Points: 1
# Comments: 0
Mudita Kompakt
Article URL: https://www.mudita.com/products/phones/mudita-kompakt/
Comments URL: https://news.ycombinator.com/item?id=49798725
Points: 1
# Comments: 0
Two JITs, Opposite Signs
Article URL: https://intertwingly.net/blog/2026/09/19/Two-JITs-Opposite-Signs.html#reading-the-columns
Comments URL: https://news.ycombinator.com/item?id=49798723
Points: 1
# Comments: 0
Researchers used Claude to hack OpenAI
We’ve heard of OpenAI’s AI agents running amok and hacking other companies. Now, a cybersecurity company has turned the tables on the ChatGPT operator by using AI to help hack OpenAI itself.
The hack, which also exposed a bug affecting dozens of other major online services, was conducted as security research. OpenAI paid the researchers for reporting a flaw in its systems through its bug bounty program.
Researchers at cybersecurity tools vendor Hacktron wrote up their adventures in mid-September. A few months earlier, they had begun looking for security flaws at companies developing frontier AI models, which are highly capable models such as those powering ChatGPT and Claude.
Using Anthropic’s Claude, the researchers went from investigating an image-processing flaw to accessing an internal OpenAI software repository in less than 72 hours. They deliberately avoided viewing sensitive information.
To get inside OpenAI, researchers Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini found two vulnerabilities and chained them together. The first wasn’t specific to OpenAI. It involved a bug in an image-upload feature in the Discourse community forum software.
This feature processes images uploaded by users and relies on a low-level software library called libheif. Uploading a specially crafted image could trigger a flaw in the library, allowing an attacker to gain control of the Discourse server.
After Hacktron used that vulnerability to compromise OpenAI’s Discourse server, the second vulnerability came into play. This was a flaw in OpenAI’s single sign-on (SSO) system, which lets people access one service using an account from another.
The SSO flaw gave Hacktron access to the ChatGPT and Codex accounts of people who had logged in to OpenAI’s Discourse forum. OpenAI uses the forum for community support, so that potentially covered a large number of accounts. Codex is an AI coding tool that helps software developers work with code.
It wasn’t just public users that had signed into this system; OpenAI employees were signed in, too, allowing Hacktron to access one employee’s account. That person’s Codex account was connected to OpenAI’s GitHub organization. GitHub is an online service that developers use to store and collaborate on software.
This gave the researchers access to OpenAI’s internal software repository.
The researchers didn’t do anything damaging with that access. They only wanted to prove that they had compromised OpenAI. So they instructed the employee’s Codex account to create a harmless pull request—a proposed software change—in an internal OpenAI repository.
OpenAI fixed its part of the problem about 14 hours after Hacktron submitted its initial report. It later paid the researchers a $6,500 bounty for the OpenAI-side flaw.
What this means for cybersecurityEthical hacking like this is commonplace, but there are some interesting aspects to this hack that make it different from many others.
The first is that Hacktron used AI to help in its efforts. It originally used Opus 4.8, one of Anthropic’s recent Claude models, to discover the issue in libheif. But it couldn’t use the model to build a reliable exploit that worked against the default version of Discourse.
Then Anthropic released Claude Opus 5. Using that model, the researchers were able to build a working exploit overnight.
That shows how quickly AI is moving. A task that Opus 4.8 had failed to complete across several sessions was solved by Opus 5 within hours of its release.
The second interesting aspect is that the researchers had to fool Claude into helping them do it. The model refused to write an exploit for a remote system because it considered the request unethical. So the researchers had to present the task as a capture-the-flag exercise (a hacking competition) to get it to play ball.
When they did that, the agent took over the test forum server within four hours. The researchers then used the resulting exploit against OpenAI’s forum. It shows that while companies may do their best to place ethical constraints on the use of their AI, a wily researcher can still get around it with some simple prompt engineering.
And it didn’t cost much to do this. Hacktron spent less than $3,000 in AI tokens during its two-month research project, which involved three researchers and uncovered vulnerabilities affecting several major companies.
The image-processing bug became the basis of a wider project called HEIF Heist. Hacktron found related security weaknesses affecting services and software from companies including Slack, Meta, and GitHub. Tweaking the HEIF exploit to target a new company took a day or two on average.
All of this lowers the bar for sophisticated hacking even further. People have been able to use ready-made hacking tools for years without really understanding how they work, but it took real expertise to pick through software, find hidden flaws, and turn them into reliable exploits.
Hacktron says skilled human guidance was still important and that this was not completely autonomous hacking. Even so, AI is making some of that expertise cheaper and faster to apply—and it’s only getting better.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
Is Claude 20x actually 20x?
Im seeing more and more about how Claude 20x is actually not 20x and its getting "dumber". I thought I was going crazy because I legitimately thought maybe I was doing something wrong but I haven’t changed any of my practises and approaches for at least a month or two and it’s definitely gotten way dumber and making way more errors and I’m having to redo a lot of work and while at the same time it’s just burning through tokens
https://www.reddit.com/r/ClaudeCode/comments/1wn0xn9/max20x_is_now_just_15_times_better_than_max5x/
https://www.reddit.com/r/ClaudeAI/comments/1wl6wyn/its_time_to_cancel_your_subscriptions_anthropic/
Comments URL: https://news.ycombinator.com/item?id=49798699
Points: 2
# Comments: 0
Show HN: DiagramHub – A central hub for draw.io diagrams with SSO
Article URL: https://diagramhub.app
Comments URL: https://news.ycombinator.com/item?id=49798680
Points: 1
# Comments: 0
Detecting and Tracking Flying Objects
Article URL: https://intellycode.dev/case-studies/drone-detection
Comments URL: https://news.ycombinator.com/item?id=49798673
Points: 1
# Comments: 0
Nvidia boss says there is '0% chance' AI destroys the world by 2030
Verda (Finland) raises $189M in Series B
Article URL: https://verda.com/blog/what-189m-in-funding-unlocks-for-verda-customers
Comments URL: https://news.ycombinator.com/item?id=49798597
Points: 1
# Comments: 0
Pygmalion's Passion
Article URL: https://paulkingsnorth.substack.com/p/pygmalions-passion
Comments URL: https://news.ycombinator.com/item?id=49798590
Points: 1
# Comments: 0
What Shopify Theme Automation Can Safely Handle and What Still Needs Engineers
Article URL: https://shugert.com.mx/blog/shopify-theme-automation-safety-boundary
Comments URL: https://news.ycombinator.com/item?id=49798557
Points: 1
# Comments: 0
