Register and share your invite link to earn from video plays and referrals.

SlowMist
@SlowMist_Team
SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.
Joined April 2018
410 Following    89.8K Followers
๐Ÿšจ SlowMist TI Alert: Muse Zero-Day ๐Ÿšจ According to a disclosure by @patrickwardle, a zero-day vulnerability in Muse for Mac could allow a local process without special privileges to hijack the AI assistant by modifying an undocumented setting. โš ๏ธ The flaw can redirect dictated prompts to an attacker-controlled endpoint, potentially enabling: ๐ŸŽ™๏ธ Prompt/audio capture ๐Ÿ’‰ Prompt injection ๐Ÿ”‘ Theft of authentication material ๐Ÿ“ฑ Remote tasking of the user's connected mobile devices Since Muse can access user-authorized data such as messages, emails, and financial information, a successful attack could potentially expose sensitive information accessible to the assistant. ๐Ÿ›ก๏ธ Users should avoid installing or running untrusted Muse-related PoCs and monitor for suspicious local activity until mitigations are available. ๐Ÿ”Ž One of 0day PoCs:
Show more
Please don't install - it's trivial to turn Muse into the ultimate backdoor ๐Ÿ’€๐Ÿ‘€ Ya, as an AI assistant built to manage your Mac, Muse needs broad access to your digital life. But serious 0-day flaw(s) can let local malware/attackers invisibly hijack it. Let me show you. ๐Ÿงต
Show more