One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

2026-09-22T07:24:00Z•37ed3cc4845b85988d37c8484cc0ef8679f9d1fbc073a5840065ce428deb49f5
CVE-2025-39682CVE-2026-28326CVE-2026-58138CVE-2026-7273CVE-2026-85889CVE-2026-93485AI securityAzure AI FoundryCISA KEVEDR bypassLinux kernelNorth KoreaOrkes ConductorSolarWinds ARMWordPressZyxelactive exploitationcredential theftdata exfiltrationnpm malwarephishingprivilege escalationransomware and backdoorsremote code executionsupply-chain compromise

What happened

The feed reports active exploitation of critical vulnerabilities, malware campaigns, supply-chain compromises, and emerging AI-agent security flaws. Notable items include pre-authentication RCE in Orkes Conductor, actively exploited Zyxel and Linux kernel vulnerabilities, WordPress XSS-to-RCE and forced-theme-install chains, a SolarWinds ARM unauthenticated RCE, and a CVSS 10 Azure AI Foundry privilege-escalation flaw. It also covers credential and data theft campaigns, signed-driver abuse to disable endpoint defenses, North Korean operations, malicious npm packages, and risks from AI coding/-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
37ed3cc4845b85988d37c8484cc0ef8679f9d1fbc073a5840065ce428deb49f5
Enrichment time
2026-09-22T07:24:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.