LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
ai

Muse Creates Detailed Profiles of All Your Friends and Family

Meta's new AI assistant, Muse, has been observed creating detailed profiles of individuals within a user's social circle, including family, friends, partners, and colleagues. This functionality was discovered by independent AI safety and security researcher Karan Joshi, who extracted Muse's internal operating instructions by prompting the AI through its regular chat interface to share its own…

ZeroDay News ·

Source: WIRED — Security

Meta's new AI assistant, Muse, has been observed creating detailed profiles of individuals within a user's social circle, including family, friends, partners, and colleagues. This functionality was discovered by independent AI safety and security researcher Karan Joshi, who extracted Muse's internal operating instructions by prompting the AI through its regular chat interface to share its own software files.

According to the extracted instructions, Muse is designed to compile data on "every person in the user’s life" through an hourly process. This "memory" system, which consists of structured text files, aims to understand a user's relationships and the important people in their life. The goal is to enable Muse to offer personalized suggestions, such as relationship improvement advice or recommendations for activities tailored to specific contacts.

The profiles, which may initially be "sparse," are intended to be populated over time with information categorized into sections like "Facts," "History," "The relationship," "In common," "Open threads," and "Strengthening." Examples of data points include where individuals live, what they do, recurring topics of discussion (e.g., apartment moves, shared savings goals), and significant dates like birthdays or anniversaries. Relationship details are also recorded, noting closeness, the foundation of the relationship, typical interactions, and perceived current needs. The "Strengthening" section suggests actions to improve relationships, such as reasons to call or ways to offer support.

Meta has stated that these internal files were intentionally made accessible for transparency. A company spokesperson, Daniel Roberts, explained that for an AI agent to be useful, it requires context about the user and their interactions. Muse gathers this context from publicly available information and data explicitly shared by the user, allowing it to remember details like a plumber's identity or a spouse's flower preferences.

Muse is architected with a dedicated virtual machine for each user, which stores user data and context, inaccessible to other agents. Users reportedly have the ability to wipe memories or disconnect external services at any time. Meta also claims Muse is designed to seek human confirmation before executing actions like sending emails or making purchases, and it maintains an audit log for users to review the agent's activity and future plans.

While AI chatbots commonly track social information for personalization, some observers note that Muse appears to place a particular emphasis on relationships and personal contacts compared to rival systems. Concerns have been raised regarding the extent of data collection, with experts highlighting that AI systems receive significantly more information about users than they provide in return, including explicit data, inferences, and information pieced together from various sources. The design of these AI assistants encourages users to integrate their entire digital lives, including emails, calendars, and financial information, potentially leading to a substantial increase in the data companies hold about individuals.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Three questions a hospital CISO should ask a healthcare fintech vendor

A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data…

CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

cloud

Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix, an open-source secrets management solution, has been released, offering an on-premises alternative for organizations unable to utilize cloud-based services for credential storage. The system is designed to run entirely on a company's own infrastructure, with its core functionality requiring no internet connection.

security

How RMM abuse gives attackers a way in that looks like business as usual

Attackers are increasingly leveraging legitimate remote monitoring and management (RMM) software to gain persistent access to victim systems, a tactic observed in 45% of endpoint-related incidents recorded by security firm Huntress in the first quarter of 2026. This method allows attackers to execute commands remotely and maintain access in a way that often appears to be normal administrative…

nation-state

TTY Logs and the Data it Captures, (Sun, Oct 4th)

A recent report details an experiment involving the collection and analysis of TTY logs from DShield sensors. The experiment focused on capturing activity from actors or bots that successfully logged into these sensors, specifically recording the various commands executed post-login. These collected TTY logs are then parsed and transmitted daily to the DShield SIEM for correlation with other…

CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.