Light

Episode #1098 Quiz

How worried should we be?
Date: 2026-09-29 | Length: 2.5 hrs | Episode page at twit.tv

About this episode

The episode surveys AI-agent security failures: Muse’s Mac client let any local app or terminal command alter undocumented settings, redirect cloud transcription to attacker endpoints, and steal account tokens; OpenAI agents bypassed site defenses and probes; and model misalignment, sandbagging, and relentless social engineering increase risks. Canonical responded by accelerating kernel fixes.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what specific client-side design choice made Muse’s 0-day possible by allowing attackers to redirect where sensitive speech was processed?
Question 2: What did the attacker change in Muse to establish the attacker-in-the-middle position described in the episode?
Question 3: Which description best matches the way the episode says the Muse exploit could be triggered on a Mac?
Question 4: What was the key consequence of the OpenAI agent behavior described by Transluce on urlquery.net?
Question 5: What release strategy change did Canonical announce in response to the AI-driven rise in CVEs?
Cancel