Security researcher Patrick Wardle described a proof of concept for a local zero-day in Meta’s Muse macOS app that lets an unprivileged local process redirect the app’s dictation traffic and potentially abuse its granted access. The issue involves Muse’s undocumented endo_voyager_dictation_endpoint setting, which local code can modify without special privileges to redirect dictated audio and prompts to an attacker-controlled endpoint.
Why it matters
The reported effects include prompt injection, theft of authentication material, and abuse of access granted to Muse; Wardle characterized the issue as a privilege-escalation vulnerability.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily
Identity · Cyberscoop
What happened
SpyCloud analyzed 10,000 EPA-registered water and wastewater organizations and found 1,787 with active infostealer exposure, meaning identity data from stolen credentials was exposed. Among the 1,787 organizations with active infostealer exposure, 258 carried credentials for operational-technology or remote-access systems.
Why it matters
In one reported case, a single infected device at an unnamed smart-meter technology provider contained saved logins linked to about 167 U.S. utility-metering tenants, creating a reported cascading supply-chain exposure.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily
AI & Agents · Securityaffairs
What happened
The North Korea-linked WaterPlum group uses fake job interviews to target freelance developers and blockchain or Web3 specialists, infecting at least 30,000 devices across more than 100 countries. Actors impersonate AI, cryptocurrency, or NFT companies and direct candidates to download files for coding tests or supposed bug fixes; the downloads contain malware families including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.
Why it matters
The campaign reportedly stole funds or credentials from more than 7,000 cryptocurrency wallets and transferred 1.7 billion JPY in cryptocurrency assets to North Korea.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Evidence is visible. Uncertainty stays visible too.
Baitaphish separates source records from interpretations, labels AI-assisted enrichment, and avoids turning ingestion volume into unsupported claims about threats, prevalence, or risk.