‘the only form that this kind of product can take is a botnet factory’

https://www.youtube.com/watch?v=HytNZfilDJs&list=UU9rJrMVgcXTfa8xuMnbhAEA - video
https://pivottoai.libsyn.com/20260928-metas-muse-ai-agent-a-hilarious-security-disaster - podcast

time: 6 min 59 sec

you are viewing a single comment's thread
view the rest of the comments
[–] 4 points 5 days ago

The best (worst) part of all is that Jonny keeps going to meta and being like "hey this is bad" and theyre like "nah that's intended behaviour"

This morning he confirmed that it's possible to get unlimited arbitrary and untraceable access to their LLM infra through these containers and that meta said that's "intended behaviour"

From jonny:

So, summary: There is arbitrary inference that is root accessible, everything runs as root, agents can be spawned, exfil is trivial, and a malicious binary can come onto the user's system through casual prompting, explicit code-sharing through the yet-to-be-released Spaces feature, walked through by a Workflow-Backed Idea, or inspired by a Generated Idea. The also yet-to-be-activated fleet learning system is a system for sharing Ideas in the background between muse instances. coming into focus?

  • source