Amazon Blocks Meta’s Muse AI Over Security Concerns
Your AI shopping assistant may need more than your permission.
Amazon has blocked Meta’s Muse AI agent from shopping on Amazon.com, citing concerns about how the assistant accesses customer accounts and handles sensitive data.
Amazon says Muse doesn’t identify itself while browsing and can access account pages and order histories and conduct transactions without the retailer’s consent. Amazon also raised concerns about credential handling, although Meta says Muse cannot see users’ passwords or payment details and stores credentials securely.
The dispute comes as Amazon pushes back against outside shopping agents from Perplexity, Google, and OpenAI. But don’t worry, Amazon isn’t against all AI shoppers—it happily allows its own agent, Alexa for Shopping, to buy items on users’ behalf.
The real issue might just be the bottom line: Automated bots don’t look at the sponsored product placements that earned Amazon $68 billion in ad revenue last year.
UK Cyber Reporting Rule Finds Most Teams Unprepared
A mere 10% of UK IT, compliance, and security professionals surveyed by compliance training firm VinciWorks actually believe they can hit a proposed 24-hour cyber incident reporting deadline under the Cyber Security and Resilience Bill.
This looming legislation drags MSPs, data centers, and certain critical suppliers into the regulatory spotlight, demanding an initial notification to regulators within 24 hours and a fuller report at the 72-hour mark.
Yet 38% of respondents admit they only comply in theory because they haven’t actually tested their escalation protocols, while others remained unsure or still working toward readiness. Nothing says “we’re secure” like crossing your fingers.
For MSPs, prepare for grueling client interrogations over breach notification clauses, escalation paths, and incident-response responsibilities. You might want to figure that out before the £100,000 (roughly $133,000) daily noncompliance fines kick in.
Gyazo Breach Exposes 490M Screenshot Records
A Gyazo breach exposed 23.62 million user records and 490 million metadata records after an attacker compromised an upload server.
The exposed metadata adds another layer of risk, including IP addresses, location data, screenshot text, image IDs, and source URLs.
Attackers could piece together years of this data to map internal systems, track locations, and build more targeted attacks.
Audit shared screenshots for exposed secrets, rotate active credentials, and restrict sensitive data from future captures.
Apple Fixes 126 Security Flaws in iOS 27
Apple patched 126 vulnerabilities in iOS 27, including 20 kernel flaws and issues affecting WebKit, Bluetooth, authentication, and sandboxing.
None were known to be actively exploited at release, but several could lead to privilege escalation and sandbox escapes.
Apple’s use of AI-assisted research shows how vendors could catch more vulnerabilities before software reaches users.
Verify managed Apple devices are running the latest version and enforce update compliance through MDM.
CrowdStrike Links Bug Hunter to Malware Campaign
CrowdStrike linked PhantomRaven malware to a bug bounty hunter who allegedly used malicious npm packages to compromise developers.
The operator allegedly used the stolen access to find vulnerabilities and collect bug bounties.
As a former pen tester, the ethical line is clear to me. Finding a vulnerability doesn’t justify unauthorized access to discover it.
Restrict developer credentials, approve trusted npm dependencies, and alert on unexpected access to GitHub and CI/CD secrets.
RatHat Malware Takes Control of Android Phones
Researchers uncovered RatHat, Android malware that can impersonate Chrome and steal credentials, authentication codes, and PINs.
Rather than exploiting Chrome, RatHat tricks users into sideloading it before abusing Accessibility and Wireless Debugging to gain deeper control of the device.
If malware can use AI to understand what’s on the screen and adapt its next move, interface changes that once disrupted scripted attacks may become less effective.
Block unauthorized sideloading, restrict Accessibility permissions, and monitor managed devices for unexpected Wireless Debugging activity.
ShinyHunters Hacks Clop Ransomware Gang
ShinyHunters breached and defaced Clop’s ransomware leak site and is now attempting to extort the group with data it claims to have stolen.
The group says it obtained source code, server logs, and Clop’s Tor private keys, although those claims have not been independently verified.
The real value for defenders may come if ShinyHunters publishes Clop’s stolen data. Server logs, source code, and infrastructure details could expose indicators and operational patterns that help security teams better track the group.
Review existing Clop detections and hunting queries as new indicators emerge from the breach.