Lookonchain APP

App Store

Muse Exposes Zero-Day Vulnerability, Allowing Local Programs to Hijack Agent Permissions

54 minutes ago

Beating AI News Flash: Meta’s personal AI agent Muse, launched just two weeks ago, has been discovered with a local zero-day vulnerability by security researcher Patrick Wardle. Attackers only need to run a piece of code on a Mac under the current user’s identity to modify a hidden Muse setting, redirecting voice requests to their own server. This code does not require extra macOS permissions. Post-exploitation, attackers can intercept users’ voice inputs to Muse, inject malicious commands, and potentially obtain Muse’s authentication credentials. Muse itself has access to system resources such as files and cameras; whatever permissions users grant Muse, malicious programs could leverage Muse to abuse those access rights. Notably, this is not a vulnerability enabling remote Mac intrusion—attackers must first execute the code locally on the device. When Meta launched Muse, it highlighted its security design, which includes the Muse Secure VM and an independent Sentinel Agent. The first zero-day vulnerability, however, was found in a hidden setting on the Mac client that can be modified by a regular local process.

Relevant content

Cardano has joined the x402 software suite, positioning itself for AI agent payments.

Cardano has been integrated into the official x402 software suite, enabling developers to build applications and AI agents that support payments in ADA and Cardano network tokens, allowing AI agents to complete on-chain payments directly for services like online data and computing resources. Launched by Coinbase in 2025, x402 converts the HTTP "402 Payment Required" status code into a native payment mechanism: service providers return pricing and payment instructions, AI agents sign transactions and access data or computing services after payment verification, eliminating the need for manual account registration, bank card details input, or subscriptions. Cardano Foundation engineers finalized the relevant specifications in June this year, and developed the client, server, and Facilitator component responsible for transaction verification and submission. The first version currently supports TypeScript, with a Python version planned for future release. However, the Facilitator has only completed actual transaction tests on Cardano’s pre-production network and has not yet been deployed on the mainnet, so it cannot yet be confirmed that ADA has achieved large-scale commercial AI agent payments. Solana, the XRP Ledger, and multiple Ethereum-compatible networks already support x402, and Cardano is joining the competition in AI agent machine payment infrastructure.

2 minutes ago

JPMorgan Chase CEO: Global AI infrastructure spending likely to exceed $1 trillion by 2027

Beating AI News: JPMorgan Chase CEO Jamie Dimon stated that the global "hyperscale cloud vendor ecosystem" – including large cloud computing firms and their upstream and downstream suppliers – is expected to spend approximately $700 billion on AI infrastructure this year, more than doubling from around $300 billion last year, and could further exceed $1 trillion by 2027. Dimon noted this round of AI investment is expanding into data centers, chips, servers, power, and industrial infrastructure, with annual new investment equivalent to roughly 1% of U.S. GDP, which may drive inflation in the short term. As AI data center construction accelerates, infrastructure such as land, power, transformers, gas turbines, and transmission lines has also become new investment priorities. He also pointed out that not all AI investments will generate clear returns in the short term; some outlays are closer to costs tech giants must bear to maintain their competitive positions. The market is increasingly focused on whether, as AI infrastructure investment moves toward the trillion-dollar scale, related revenues and cash flows can cover the continuous expansion of capital expenditures.

2 minutes ago

Veteran meme coins rallied across the board, with Dogecoin (DOGE) surging over 18% and Pepe (PEPE) jumping more than 32%.

According to HTX market data, established meme coins are seeing a broad rally, with the following 24-hour gains: PEPE up over 32%, DOGE up over 18%, FLOKI up over 15%, WIF up over 27%, SHIB up over 12%, and BONK up over 16%.

2 minutes ago

Goldman Sachs: AI pushes the supply of cultural and entertainment content toward near-unlimited levels, while the value of the production segment may remain under pressure.

Beating AI News Flash: Goldman Sachs’ latest research report points out that AI is reshaping China’s cultural and entertainment industry value chain. With content supply approaching infinity while user time and attention remain limited, this contradiction will drive industry profits to further concentrate on top IPs and distribution platforms. The report shows multimodal AI has cut production costs for animation, music, ad videos, short dramas and other content by 80% to 95%, lifting production efficiency by 5 to 10 times. In the first 8 months of 2026, the output of short dramas and miniseries grew 13 times compared to the full year of 2025, while new game releases increased by over 8 times. At leading short drama platform Hongguo, over 90% of episodes now use AI-generated content. Goldman Sachs notes that the boom in content supply brought by AI does not mean all segments of the industry chain will benefit. The value of traditional production and execution links will be compressed, while the scarcity of top IPs and creative assets will become more prominent. Content distribution platforms are expected to benefit from increased supply, but their competitive barriers built on copyrighted content libraries may be impacted by the flood of AI-generated content. In terms of specific sectors, Goldman Sachs believes online gaming is relatively more resilient, with leading players like Tencent and NetEase expected to leverage AI to extend the lifecycle of mature IPs. Long video platforms may see short-term benefits from lower costs, but face long-term pressures including declining user time and AI content eroding their advantages in copyrighted content. Additionally, AI-driven cultural entertainment still faces two major risks: monetization challenges and stricter regulation.

2 minutes ago

Coinbase CEO responds to stablecoin yield controversy: Fundamentally distinct from bank interest, so they do not need to be subject to bank capital and liquidity requirements.

Coinbase CEO Brian Armstrong recently appeared on the Money Rehab podcast to address the difference between USDC holder rewards and bank interest, as well as whether Coinbase should adhere to bank capital and liquidity regulatory requirements. Armstrong clarified that the "rewards" users receive for holding USDC on Coinbase are not interest. The underlying USD is allocated to short-term U.S. Treasuries (yielding approximately 3.5%-4%), with a portion of the returns passed back to users—similar to a loyalty program. Bank interest, by contrast, derives from the fractional reserve system, where banks lend out customer funds and assume corresponding risks. To explicitly distinguish the two, Coinbase intentionally uses the term "rewards". In response to calls for crypto platforms to be held to the same capital, liquidity, and FDIC insurance standards as banks, Armstrong emphasized that stablecoins must maintain 100% reserves under the GENIUS Act, with funds held in short-term U.S. Treasuries. This structure eliminates fractional reserve risks and the potential for bank-style runs. Banks face strict regulation due to their higher operational risk, while stablecoins have an inherently different framework. He criticized large banks for lobbying to limit competition, stating this harms consumer interests. Meanwhile, Armstrong noted that Coinbase is assisting both community banks and large banks in integrating stablecoin technology, with the goal of mutual benefits for all parties. These remarks come as the Clarity Act encounters obstacles in the Senate. Armstrong believes U.S. crypto regulatory clarity will eventually be achieved, whether through legislation or regulatory agency rules.

2 minutes ago

North Korea-linked hacker group TraderTraitor launches a new round of attacks using a malicious Terraform project.

According to SlowMist, North Korea-linked threat actor TraderTraitor (also known as UNC4899 and Jade Sleet) has launched a new attack, recently infiltrating an Indian IT services firm with no ties to the crypto industry. The attacker posted fake job listings on GitHub, using "technical interview assignments" as bait to phish DevOps and crypto engineers. After victims download the project, a malicious .terraform.lock.hcl file points to a Terraform Provider domain controlled by the attacker. Running `terraform init` triggers the download and execution of the malicious Provider module. The attack deploys Rust/ARM64 backdoors FLATROOF and ROOFDECK on victims’ macOS devices; these two malware families were previously used in LayerZero attacks. They can steal credentials and sensitive data, execute shell commands, collect and exfiltrate files, and gain access to cloud services and code repositories. SlowMist warns that TraderTraitor’s latest targets are no longer limited to the crypto sector—the attacker may now be focusing on developers’ access to cloud and API services including AWS, GCP, OVH, and OpenStack. Enterprises should exercise caution when handling unfamiliar Terraform Providers and code repositories from recruiters, and avoid using personal or work devices to run unvetted interview projects.

2 minutes ago

Popular tokens

BitcoinEthereumHyperliquidSolanaTRONBNBTetherAaveXRPPepeFartcoinOndoJupiterUniswapBonkPendleEthenaArbitrumAvalancheLidoChainlinkPolygonDogecoinCardano