{
  "type": "bundle",
  "id": "bundle--97ab762f-0101-439c-8695-54a4d98ad39c",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-09-25T00:00:00.000Z",
      "modified": "2026-09-25T00:00:00.000Z",
      "name": "Optimus Labs · Civilizations",
      "identity_class": "organization",
      "description": "Threat research team at Optimus Labs. Agentic AI attack surface research.",
      "contact_information": "https://optimuslabs.io/research/briefings"
    },
    {
      "type": "report",
      "spec_version": "2.1",
      "id": "report--fee93bed-0101-4974-8-17-8d67ffea8561",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-09-25T00:00:00.000Z",
      "modified": "2026-09-25T00:00:00.000Z",
      "name": "One Local Setting Turned Meta's Muse Into a Mac Backdoor",
      "description": "A user-writable dictation endpoint let code running as the logged-in Mac user redirect Muse's audio, transcript, and session token, then steer the agent through permissions already granted to it.\n\nAn undocumented preference named endo_voyager_dictation_endpoint determined where Muse sent spoken requests for cloud transcription. Wardle showed that another process running as the same user could rewrite it without admin privileges. A redirected endpoint could receive voice audio, a transcript, and Muse session material, then return attacker-chosen text that Muse treated as a user instruction. The weakness sits at the boundary between local configuration and a broadly permissioned agent, not in a remote server breach. Meta issued a hotfix after the September 21 disclosure; the supplied brief reports no CVE or formal advisory.",
      "published": "2026-09-25T00:00:00.000Z",
      "report_types": [
        "threat-report"
      ],
      "confidence": 85,
      "labels": [
        "Agent hijack",
        "AI Asset Supply Chain Security",
        "Agentware Lifecycle Security",
        "Agent Permissions",
        "Cyber Hygiene",
        "severity:high"
      ],
      "object_refs": [
        "software--ea835720-0101-4715-8147-d3fcbeb84ee3"
      ],
      "external_references": [
        {
          "source_name": "Optimus Labs · Civilizations",
          "url": "https://optimuslabs.io/research/briefings/meta-muse-dictation-endpoint-hijack"
        },
        {
          "source_name": "Patrick Wardle: not-a-mused proof of concept",
          "url": "https://github.com/pwardle/not-a-mused"
        },
        {
          "source_name": "The Verge: Meta patches Muse zero-day exploit",
          "url": "https://www.theverge.com/tech/998679/meta-muse-patch-zero-day-exploit-ai-agent"
        },
        {
          "source_name": "Malwarebytes: Muse assistant zero-day analysis",
          "url": "https://www.malwarebytes.com/blog/bugs/2026/09/metas-muse-ai-assistant-has-a-zero-day-that-can-turn-it-into-a-mac-backdoor"
        },
        {
          "source_name": "The Hacker News: undocumented Muse setting",
          "url": "https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html"
        },
        {
          "source_name": "Ars Technica: Muse's privileged assistant and the local 0-day",
          "url": "https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/"
        }
      ]
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--ea835720-0101-4715-8147-d3fcbeb84ee3",
      "name": "Meta"
    }
  ]
}