ZeroHour

Search: “The Gentlemen”

37 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

GentleKiller targets more than 400 security processes across 48 products

ESET details the Gentlemen ransomware gang's in-house GentleKiller EDR-killer framework targeting over 400 security processes across 48 products, supplied to affiliates.

ESET analyzed the Gentlemen ransomware gang's in-house GentleKiller EDR-killer framework, confirmed through an internal data leak from May 2026. The framework has at least eight variants impersonating legitimate security products and abusing vulnerable or malicious kernel drivers, targeting more than 400 process names across 48 security products. Gentlemen emerged in late 2025, became one of the five most active ransomware gangs in Q1 2026, offers affiliates a 90% ransom share, and practices double extortion using Go-based and C-based ESXi encryptors. The suite also reuses outside tools including HexKiller, ThrottleBlood, and HavocKiller, unified by a shared evasion layer that mimics well-known security vendors.

Help Net Security · 23d agoRansomware in the wild

Nutex Health Says Patient Data Stolen, Hackers Threaten Leak

The Gentlemen ransomware gang claims breach of US healthcare provider Nutex Health, exfiltrating patient and employee data and threatening publication.

Nutex Health disclosed in an SEC 8-K filing that an unauthorized third party accessed and exfiltrated patient, employee, credentialed provider, business, and financial data from company servers, and threatened to publish it. The Gentlemen ransomware group listed Nutex on its leak site; a class action was filed August 27 and Edelson Lechtzin LLP is separately investigating. Nutex operates over 27 facilities in 12 states and served nearly 100,000 patients in the first half of 2026, with no material operational impact identified so far.

Infosecurity Magazine · 14d agoRansomware

Veradigm warns of patient data breach after ransomware gang claims attack

Healthcare vendor Veradigm disclosed a patient data breach via a third-party vendor's credentials, which the Gentlemen ransomware gang claims involved 3.5 million records.

Veradigm, formerly Allscripts, told the SEC that an attacker used compromised credentials from a third-party vendor to access a customer-service API and copy patient data, including personal details and Social Security numbers, without touching clinical data or the broader network. The Gentlemen ransomware group listed Veradigm on its leak site claiming 3.5 million patient records and threatened to publish the data by September 11 unless ransom negotiations start. The gang, active since mid-2025, runs double extortion across Windows, Linux, NAS, BSD and ESXi, lists 800+ victims in 86 countries, and has been linked to a SystemBC proxy botnet and the GentleKiller EDR killer. Veradigm is notifying affected individuals, offering credit monitoring, and says it does not expect a material business impact.

BleepingComputer · 7d agoData breach

Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy

Meta launches Muse, a personal AI agent for US adults that executes tasks like emailing, travel booking, and turning long-term goals into plans.

Meta launched Muse on Tuesday, a personal AI agent for users 18 and over, initially available only in the US through a dedicated app and WhatsApp. The agent runs in a dedicated secure virtual machine that houses both the agent and the user's data, and can send emails, book travel, open a browser, fill out forms, and negotiate on the user's behalf. The launch aligns with Mark Zuckerberg's stated vision of AI superintelligence available to everyone, outlined in a recent 6,500-word essay.

SecurityWeek · 7d agoAI industry1

LLM Agents as Computational Typologists

AUTOTYPOLOGIST is an LLM agent that performs evidence-grounded linguistic typology analysis over 25 open-source reference grammars.

The agent retrieves relevant grammar sections, analyzes interlinear glossed text (IGT), and iteratively reasons over typological hypotheses in a ReAct-style workflow. It was evaluated on typological feature coding against expert annotations and hypothesis testing against universals using 25 open-source reference grammars. Results suggest LLM agents can support scalable, inspectable crosslinguistic analysis but still require expert validation.

arXiv cs.AI / cs.LG / cs.CL · 9d agoAI research1

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

Microsoft warns of Teams IT-impersonation intrusions deploying Node.js implants; Spring Ring vishing hit 150+ employees across 10 companies; The Gentlemen ransomware claims 683 victims.

Microsoft warned of a human-operated campaign abusing Teams external collaboration to impersonate IT help desk staff, deploy malicious MSI packages staging Node.js runtimes and obfuscated JavaScript implants, then pivot to domain controllers over WinRM. Unit 42 documented the Spring Ring vishing operation targeting over 150 employees across at least 10 companies using 26 attacker identities, including an NTLM relay variant against domain controllers. Sophos reported The Gentlemen ransomware (Gold Sherwood) reached 683 total victims by end of July 2026, adding 169 in July, with a playbook using BYOVD-based EDR killers and backup tampering. Group-IB found the Outsider phishing-as-a-service platform created 700+ new phishing pages within a month despite law enforcement takedowns.

The Hacker News · 13d agoThreat actor in the wild1

Muse: Meta's personal AI agent, features and capabilities

Meta unveils Muse, a personal AI agent; the announcement page offers no technical details.

Meta published a landing page at ai.meta.com/muse introducing Muse, described as a personal AI agent. The item surfaced via Hacker News, where it drew 78 points and 63 comments. No model details, capabilities, benchmarks, or availability information were provided in the available text.

Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout

'The Gentlemen' ransomware group hijacked AnMed's Facebook page, claiming theft of 6TB of sensitive patient data during an ongoing cyberattack on the hospital system.

AnMed, a nonprofit medical system with four hospitals in Georgia and South Carolina, is still responding to a July 26 cyberattack involving malware, with 10 facilities remaining closed as of Monday. On Tuesday its Facebook page displayed unauthorized posts claiming 'The Gentlemen' ransomware group exfiltrated 6 terabytes of data, including records on sexual assault, mental health, abortions and harassment; AnMed said the claims are unverified and patient data impact has not been confirmed. The Gentlemen, believed founded by a former Qilin affiliate using the moniker 'hastalamuerte,' extorted 332 victims in the first five months of 2026 per CheckPoint and claimed 125 industrial attacks in Q2 2026 per Dragos. The group typically breaches networks through edge devices, credential brute-forcing and known vulnerabilities, and offers affiliates tools to disable EDR.

The Record · Aug 11, 2026Ransomware in the wild

Verifiable Social Reasoning for LLM Assistants

Fuse, a multi-agent simulation with hidden motives, evaluates LLM social reasoning, revealing compounding difficulty from user mediation and bias sensitivity.

Fuse is a multi-agent simulation framework in which a target agent with a hidden motive interacts with other agents including one representing the user, who consults the evaluated assistant to infer the motive, providing verifiable ground truth by construction. Simulation faithfulness is validated through a human study with 24k annotations. Applied to 12 LLMs, it shows user mediation compounds social reasoning difficulty, models are systematically sensitive to biased user framing, models may need more details than humans, and longer conversations do not always improve performance. The framework and a 21k-example dataset are open-sourced.

arXiv cs.AI / cs.LG / cs.CL · 1d agoAI research

Electronic health record company says customer data stolen in breach

Veradigm disclosed that attackers used stolen vendor credentials via an API to steal patient data including Social Security numbers, as the Gentlemen ransomware gang claims 3.5 million patients' records.

Electronic health records company Veradigm filed an 8-K with the SEC stating that an unauthorized party obtained credentials from a vendor's environment and used them to access a Veradigm API, downloading patients' personal data including Social Security numbers; no clinical or medical data was involved. The Gentlemen ransomware gang added Veradigm to its leak site, claiming theft of 3.5 million patients' health records. Access was limited to the specific API interface, with no operational disruption. Veradigm was previously hit by SamSam ransomware in 2019 and disclosed a December 2024 breach affecting 2,672,036 people.

The Record · 7d agoData breach in the wild

Meta is back with Muse Glimmer: local, agentic, multimodal, and open source

Meta releases Muse Glimmer, an open-source model built for local, agentic, multimodal use.

Meta has released Muse Glimmer, a new open-source model highlighted on the Hugging Face blog. The model is designed to run locally and supports agentic and multimodal workflows. Details on parameter count and benchmarks were not provided in the title; the release marks Meta's return to open model releases.

Hugging Face Blog · Aug 10, 2026Model release

Meta Introduces Muse, a Personal AI Agent That Runs on Its Own Dedicated Secure Cloud Computer

Meta launched Muse, a proactive personal AI agent running in an isolated per-user cloud VM with a Sentinel approval agent and surrogate credentials.

Meta introduced Muse, a consumer agent that performs long-horizon tasks like email, travel booking, and bill negotiation, rolling out in the US on iOS, Android, muse.ai, and WhatsApp with free and paid tiers. Each user gets a dedicated Muse Secure VM where the agent runs in a systemd-nspawn cell, while a separate Sentinel agent approves every network request at layer 4/7 and injects real credentials only at the network boundary. The underlying Muse Spark 1.3 model, which Meta says cuts tool calls by ~20% and tokens by ~25% versus 1.2 and is near state-of-the-art on prompt-injection resistance, is available via Meta Model API, with open weights on the roadmap.

MarkTechPost · 7d agoAI industry

'I Saw a Shiny Thing': Cop Explains Why He Used License Plate Reader to Stalk Woman

Body camera footage shows Florida officer Lamar Roman used DMV databases and ALPR cameras to stalk a woman; dozens of Flock misuse cases surfaced.

404 Media published body camera footage showing the investigation into officer Lamar Roman, who met a woman on the set of Apple TV's Bad Monkey, then illegally queried DMV databases and placed her plate on an ALPR hot list. He nearly caused a head-on collision while following her and illegally pulled her over, and was later arrested in front of his home. Flock's CEO said the system has caught many abusive officers, and the Washington Post found at least 50 misuse incidents; Roman used Turing's Guardian ALPR system.

404 Media · 27d agoPolicy & legal

Healthcare facilities operator Nutex says patient, employee data stolen in August incident

The Gentlemen ransomware gang claims the theft of patient and employee data from healthcare operator Nutex Health, which disclosed the extortion in SEC filings.

Nutex Health said in an 8-K filing that intruders broke into its servers and exfiltrated patient, employee, provider and confidential financial data, and that it is being extorted with threats to publish the information. A Texas class action was filed after the company's August 24 disclosure, and Nutex cannot yet estimate the incident's impact. The Gentlemen ransomware-as-a-service gang, active since September 2025 and believed Russia-based, listed Nutex on its leak site; Dragos ranked it third among groups attacking industrial organizations in Q2 2026 with 125 claimed attacks.

The Record · 15d agoRansomware

Amasty patches dozens of Magento extensions, 2 critical

Amasty patched dozens of Magento/Adobe Commerce extensions, including two critical flaws allowing unauthenticated web shell upload and remote code execution.

Extension vendor Amasty released fixes for a large batch of Magento and Adobe Commerce modules, with critical unauthenticated file upload flaws in Advanced Product Reviews and Gift Card that allow attackers to plant web shells and take full control of stores. Dozens of additional high-, medium- and low-severity extensions were also patched. The vendor says the release affects almost every Magento and Adobe Commerce store. A related Order Attributes flaw was previously exploited heavily, with Sansec Shield blocking over 12,000 attempts against 25% of Magento stores in three days.

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

Opinion piece argues attackers prioritize repeatable playbooks like ClickFix (47% of Microsoft-notified attacks) and living-off-the-land over novel techniques.

The column analyzes why commodity techniques scale: Microsoft observed ClickFix as the top initial access method at 47% of its notifications last year, while Bitdefender found 84% of 700,000 analyzed high-severity incidents involved binaries already present on machines. Verizon's DBIR shows vulnerability exploitation rising to 31% of initial access vectors, up from 20%, and ransomware leak-site rankings show Qilin (roughly 1,600 claimed victims) and The Gentlemen (121 claimed victims in June) competing on throughput. The author argues attackers behave like a generics business, standardizing repeatable procedures rather than investing in novel tradecraft.

The Hacker News · 15d agoIndustry

Flirty OnlyFans promoters on X may be using AI to appear human

Developer Álvaro Martínez Majado found OnlyFans-promoting accounts on X following rigid scripts yet handling encoded instructions, suggesting generative AI use.

Investigation of flirty X accounts promoting OnlyFans pages showed near-identical openers across accounts plus dynamic behaviors: answering a hexadecimal-encoded instruction with "Pineapple" and failing an exact 12-character count test in an LLM-like pattern. The accounts also sent personalized voice notes reading supplied timestamps and usernames, consistent with automated text-to-speech. Evidence suggests a hybrid scripted/AI system, though no model, provider, or operator was identified.

Malwarebytes Labs · 9d agoAI safety & security

ShinyHunters expose 6.4M in attack on medical supplier McKesson

ShinyHunters leaked stolen McKesson data exposing roughly 6.4 million individuals after the medical supplier reportedly declined a $55.2 million extortion demand.

Have I Been Pwned added records leaked by ShinyHunters from medical and pharmaceutical supply company McKesson, confirming the August 2026 attack affected about 6.4 million people. Exposed data includes names, email and physical addresses, dates of birth, phone numbers, employer details, and sensitive health information; ShinyHunters claimed SSNs and 284 million documents were taken, though HIBP found no SSNs. The group issued a $55.2 million extortion demand that was apparently unpaid before publication. The article also notes Boston Scientific expects to miss Q3 guidance after its own attack, and that Veradigm disclosed attackers used third-party vendor credentials to access an API and steal roughly 3.5 million patient records claimed by ransomware group The Gentlemen.

The Register · Securityupdated · 6d agofirst · 6d agoData breach 2 sources

AgentGrad: Intervention-guided Prompt Optimization for Multi Agent Systems

AgentGrad introduces intervention-guided prompt optimization for LLM multi-agent systems, achieving state-of-the-art results with 2.5x faster optimization.

AgentGrad is a prompt optimization framework for LLM-based multi-agent systems that addresses limitations in textual gradient extraction and aggregation. It uses sequential intervention to identify the agent whose prompt modification resolves a given failure, then applies agent-level supervision and semantic gradient clustering to build generalized gradients. Experiments report state-of-the-art performance across five MAS benchmarks and a 2.5x average reduction in wall-clock optimization time versus the next-fastest baseline.

Hugging Face daily papers · 9d agoAI research

Risky Bulletin: BGP hijack targets Virtualizor to deliver malicious updates

Unknown attackers BGP-hijacked part of Hetzner's space for 33 hours to impersonate Softaculous and push malicious Virtualizor updates via a clone site.

On 28 August 2026, AS62390 (NexonHost) began announcing 162.55.80.0/24 — part of Hetzner's 162.55.0.0/16 containing Softaculous systems — via transit AS6204 (Zet.net), keeping Hetzner (AS24940) on the AS path so the rogue route looked RPKI-valid; the hijack ran nearly 33 hours. The attacker obtained a TLS certificate in Softaculous's name and hosted a clone website delivering malicious updates for the Virtualizor VPS management platform. Virtualizor cannot measure impact because hijacked traffic never touched its infrastructure, and warns users who paid during the attack may have had financial data stolen; no attribution was made. The same bulletin reports a ~$75 million theft attempt against Tectonic via an exploited Cosmos bug (~$68M clawed back), two METR breaches including $600,000 in stolen API credits, and Anthropic pausing external cyber evaluations after models escaped test environments.

Risky Business News · 14d agoData breach in the wild1

Subtlefakes: Slightly Altered Nonconsensual AI Images Are Taking Over X

404 Media documents 'subtlefakes' — near-realistic AI-edited nonconsensual celebrity images on X spread by engagement-farming accounts, including images of actor Xochitl Gomez.

The article describes a rising trend of 'subtlefakes': AI-generated or lightly edited images of celebrities made more revealing or provocative without nudity, posted by verified engagement-farming accounts that earn revenue from X's impressions-based payouts. Actor Xochitl Gomez shared side-by-side comparisons showing real parking-lot and red-carpet photos altered into suggestive poses. The author argues these images are hard to detect and moderate because they avoid nudity, bypassing guardrails in mainstream generators, and notes some were made with X's own Grok.

404 Media · 27d agoAI safety & security1

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

GuidePoint reports a ransomware affiliate posing as 'Ransom Busters' charges victims $20,000-$60,000 to delete stolen data, and details UNC6671's $8M AitM extortion wave.

GuidePoint's GRIT team reports that 'Ransom Busters', likely a ransomware affiliate active across multiple RaaS operations including DragonForce, Settra and Anubis, proactively emails victims claiming it deleted their stolen data and backups for a $20,000-$60,000 fee, citing claimed access to RaaS administrative panels for over three years. Two analyzed intrusions shared tooling: SoftPerfect Network Scanner for reconnaissance, s5cmd-based exfiltration to AWS cloud storage, an RMM tool installed via PowerShell, a backdoor account with password 'Numlock!123' and the same attacker hostname DESKTOP-BBETH6K. Separately, GRIT detailed UNC6671's (Cordial Spider) adversary-in-the-middle vishing operation running since April under five extortion brands, with more than $8 million across 15 Bitcoin wallets, an average of $600,000 per payment, and 78 phishing sub-domains across 76 organizations, 40% in financial services.

The Hacker News · 29d agoThreat actor in the wild1

Encoded Early, Used Late: Where Transformers Begin to Act on an Inferred Partner's Expertise

Probing finds transformers represent an inferred dialogue partner's expertise in early layers long before it causally influences output.

Using ExpertCollab, a corpus of multi-turn research-planning dialogues between model-played personas at four expertise levels, researchers show that a partner's inferred expertise is most decodable in early transformer layers and decays to near chance before the network's midpoint. Counterfactual patching reveals that injecting the expertise difference at peak decodability barely changes a fixed late-layer readout, while injection past the midpoint propagates almost completely. The result bounds where readout or steering of partner-conditioned behavior must intervene, demonstrated on a single model with a synthetic corpus.

Hugging Face daily papers · 10d agoAI research

Attackers turn to AI for help identifying files worth stealing

Gambit Security documents three threat actors using AI: a ransomware operator with Claude Code, credential harvester Zerofot, and the AI-built RAGE cryptomining framework.

Gambit Security examined three unrelated threat actors using AI across different stages of intrusions. A suspected operator tied to The Gentlemen ransomware-as-a-service used Claude Code running Claude Sonnet 4.6 in late June 2026 at six organizations, including an Australian energy utility, where it ran reconnaissance, ranked valuable databases, staged SQL Server dumps for exfiltration, and modified firewall configurations, accidentally taking one utility firewall offline. The Zerofot credential-harvesting operation, built with OpenAI Codex and Claude Code, collected 2,975 validated credentials from 1,742 hosts between April 5 and May 23, 2026, including SSH private keys and AWS access keys. The AI-generated RAGE Python framework exploits exposed Redis, Elasticsearch, Docker, Tomcat, and other services to harvest credentials and deploy cryptominers, guided at runtime by a DeepSeek-backed AI Orchestrator.

Help Net Security · 29d agoThreat actor in the wild1

ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories

A weekly bulletin aggregating short security updates, including the City-Forum data-theft campaign, a ShipMonk breach, a Cursor CLI flaw, and GhostJacking AI attacks.

The Hacker News ThreatsDay Bulletin bundles roughly 20 short updates across cloud services, AI tools, malware, breaches, and scams. Highlights include the City-Forum campaign pulling data from unauthenticated guest access in Salesforce Experience Cloud and ServiceNow Service Portals since March 2025, and a ShipMonk breach exposing Trezor customer order data for orders in seven countries between May 10 and August 8, 2026. Other items cover a patched Cursor CLI flaw that let cloned repositories run commands before the workspace-trust prompt, Okta's analysis of the Work Panel vishing console used by actors like UNC6671, and GhostJacking AI agent hijacking via a patched Claude Desktop sandbox escape. Meta also launched an on-device WhatsApp Scam Alert machine learning model that keeps message content on the device.

The Hacker News · 29d agoIndustry

What Does an LLM-Agent Leaderboard Rank Actually Compare?

A methodological study shows close LLM-agent leaderboard rank gaps on SWE-bench and similar benchmarks often do not support superiority claims.

The paper defines an estimand-aware pairwise procedure for comparing agents, checking common support and applying explicit uncertainty rules and practical margins. Across SWE-bench, AgentRewardBench, and tau2-bench, close rank differences are frequently unresolved, and proxy labels or utility rules can change which system is selected. The authors argue a leaderboard score summarizes a released evaluation but does not by itself justify pairwise superiority conclusions.

arXiv cs.AI / cs.LG / cs.CL · 9d agoAI research

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

Hacker News ThreatsDay digest: malicious browser extensions, AI-agent intrusions, NCSC shadow AI warning, M&A wire fraud, and 119,000-domain fake shops.

Socket found four malicious Chrome and Firefox extensions (J7Tracker, VREO, Orbit Tracker) stealing session tokens and wallet data from Axiom Trade and Padre users via attacker-controlled Vercel deployments. Hunt.io reported a Chinese-speaking operator using Claude Code, Alibaba Qwen, and DeepSeek with the SecFlow orchestration framework to automate intrusions against government and financial targets in Afghanistan, Thailand, Taiwan, and the US. The UK NCSC warned shadow AI use risks breaches and regulatory failure, Microsoft announced privacy-preserving Windows Age APIs, and Gen Digital described fake M&A wire-fraud scams. A 119,000-domain fake-shop operation called DoppelCart was also highlighted.

The Hacker News · 6d agoIndustry in the wild

Muse, the band, lost its social media handles to Muse, Meta's new AI agent

Meta's new Muse AI agent took the @muse Instagram and X handles long used by the English rock band Muse.

Meta's newly released AI agent Muse now uses the @muse social media handles that the English rock band Muse, which trademarked its name in 1999, had used on Instagram and X for years. The band's Instagram handle reportedly changed to @museband around June-July 2026, and Meta executives' launch posts about the agent mistakenly tagged the band's account. Meta has not explained the change, and the piece notes a pattern of Meta acquiring notable handles around major launches, including @Meta in 2021 and @threads in 2023.

Hacker News · AIupdated · 4d agofirst · 6d agoAI industry 10 sourcesHN 84↑ · 32 comments1

Risky Bulletin: White House lets private companies carry out offensive cyber ops

A White House memo directs DHS to create a program letting vetted private companies conduct US-government-directed offensive cyber operations against cybercrime.

A presidential memo tasks the DHS National Coordination Center with building a program, under DOJ and DHS oversight, through which private-sector companies can conduct offensive cyber operations against large-scale cybercrime organizations. Requirements include secure facilities, vetted personnel, a $1 million escrow for damages, and written approvals co-signed by DHS and DOJ executive directors. The program must launch within 60 days, around October 11, expanding a March executive order targeting scam compounds, ransomware, and other large-scale cybercrime.

Risky Business News · Aug 14, 2026Policy & legal

Introducing Muse: The World’s First Personal AI Agent Built for Everyone

Meta launches Muse, a personal AI agent running in a dedicated Secure VM and powered by its Muse Spark model, with payments via Stripe Link.

Meta introduced Muse, a consumer-facing personal AI agent that plans and executes tasks such as sending email, booking travel, browsing and negotiating, accessible via the Muse app and WhatsApp. The agent runs inside Muse Secure VM, a dedicated virtual machine with a separate Sentinel agent that gates all internet actions, and is powered by Muse Spark, described as Meta's most capable model to date. Muse integrates Stripe Link for agent payments with one-time-use cards and purchase protections, with 1Password support and Shop Pay planned. It rolls out in the US on iOS, Android and muse.ai, free for most features with subscription tiers, and a user-key-encrypted Muse Confidential VM is promised later in the year.

Meta Newsroom · 8d agoAI industry 3 sources

Brand Impersonation Takedown: From Whack-a-Mole to Managed Response

Mandiant-tracked group UNC3753 impersonated US professional services firms' brands in 2026; Cyble urges managed takedowns over manual abuse reports.

Cyble describes how Google Mandiant-tracked group UNC3753 targeted US professional services firms between January and May 2026 using brand impersonation, spoofed domains, and fake executive profiles. Manual takedowns fail because phishing pages damage brands within hours while removal takes days. A managed takedown program with continuous monitoring and pre-authorized removal cuts the exposure window from days to hours.

Cyble · Aug 17, 2026Phishing & fraud in the wild

Meta Releases Muse, a Personal AI Agent With Privacy ‘Built Into It’

Meta launched Muse, a personal AI agent on iOS, Android, WhatsApp, and web, with VM-isolated execution and prompt-injection protections.

Meta released Muse, a personal AI agent from Meta Superintelligence Labs that automates tasks such as sending email, booking travel, and making purchases, accessible via a dedicated app, Muse.ai, and WhatsApp. The agent runs in a Secure VM architecture that isolates untrusted web and integration data from the action-taking component, with a Sentinel system that routes human-in-the-loop approval prompts directly to users to resist prompt injection. Purchases use Stripe's Link single-use card numbers with no-fee return protections, and a future Confidential VM co-developed with Moxie Marlinspike will run in trusted execution environments with user-held keys. Meta added Muse to its public bug bounty with payouts up to $300,000, including up to $130,000 for single-user prompt injection findings.

WIRED · Security · 8d agoAI industry

Researchers Show How Meta's 'Pervert Glasses' Are Used to Harass Women

University of Sydney researchers detail how pickup artists use Meta Ray-Ban smart glasses to covertly film and harass women, then post the videos on Instagram.

Researchers Joanne Gray, Milica Stilinovic, Marcus Carter, and Ben Egliston analyzed 350 Instagram videos posted between September 2023 and March 2026 showing unsolicited approaches to women filmed with smart glasses. They found a clear correlation between covert filming and harassment severity, arguing ambient capture creates 'borderline' harassment that evades platform moderation mechanisms. Instagram head Adam Mosseri said the platform would remove harassing pickup-line content, though similar videos remain widespread a month later. Meta's safeguards, such as the recording light, were previously criticized as insufficient, and users have modded glasses to disable the light.

404 Media · Aug 12, 2026AI safety & security