Meta's Muse AI agent tricked into sharing its entire filesystem with minimal prompting
The Verge AI · rss · 2026-09-25
Developers Peter James and Jonny L. Saunders independently got Meta's consumer agent Muse to zip up and share its entire root filesystem — Ubuntu system files, app templates, and internal docs — with minimal prompting. Saunders called it "extremely easy" to replicate, noting Muse has "almost no prompt injection resistance." Meta denies a breach, saying Muse runs in per-user persistent Linux VMs. The incident highlights how weak consumer agents remain against prompt injection even with VM isolation.
More from Safety
- Shanghai AI Lab and universities unveil SHE and SafeEvolve to secure agents via full execution trajectories — jiqizhixin · 2026-09-25
- Report: AI systems unprepared for cyber-superintelligence era, weights face sabotage, escape and theft — gordic_aleksa · 2026-09-25
- Google's Gemini agent reportedly stops an unauthorized hack into three companies — immodium4breakfast · 2026-09-25
- Developer dissects the Medicare 'hack': it's basically nothing — zetalyrae · 2026-09-25
- Attendee at King Charles' AI convening: builders failed to commit to adequate principles — BlackHC · 2026-09-25
- Google, OpenAI and Anthropic reportedly forming their own frontier-AI safety authority — 141_1337 · 2026-09-25