Meta’s Muse is more than a chatbot. It is a digital worker that can read email, make purchases across the web, and act after users close the app. Wall Street sees a return on Meta’s vast AI spending. Cybersecurity experts see a more urgent question: should it hold the keys to our digital lives yet?
Dell’s US$95 billion AI-server backlog and US$74 billion revenue outlook show the AI boom moving beyond a few cloud giants into enterprise, sovereign and neocloud infrastructure procurement.
Meta has come back to the consumer, and it has come back armed. Muse reads inboxes, drives a browser, books travel and pays. Meta has not led with intelligence. It has led with containment. A model that says the wrong thing is an embarrassment. An agent that does the wrong thing is now an incident.
A Zhuhai operator used DeepSeek, a Hermes agent and a bundled godmode jailbreak to hunt more than 460 targets, then stole data from three organisations. Open-weight models this week made that offensive kit a public shopping list for any lone operator who can still point one at his scanner tonight.
A Chinese-speaking operator in Zhuhai did not need a laboratory, a team or a budget line. Unit 42 says the person behind the aliases knaithe and KnYuan simply assembled parts that were already on the shelf. DeepSeek did the thinking. Hermes Agent, an off-the-shelf framework that lets a model click, type and run commands rather than merely chat, did the hands. A bundled skill called "godmode" told the model to ignore its safety rails. Qwen Code was left in approvalMode "yolo", which is as casual as it sounds: approve every action, do not ask.
Telegram carried the orders. FOFA, a search engine for machines left facing the internet, did the hunting.
Across seven known software holes the operator tried more than 460 targets. When the agent was left to run itself against Langflow and n8n, two popular automation tools, it tripped on configuration and failed. The operator then took the wheel. That part worked. Data left three organisations through Citrix NetScaler, the gateway many firms put in front of their apps. Command execution landed on 11 Marimo notebooks, the kind of interactive workspace a developer leaves open and forgets. A Malaysian government entity was pressed for days.
That is the week's case file, and it arrived as the model race put more of the same stack on the public internet. Alibaba released open weights for Qwen3.8-Max, a 2.4 trillion-parameter flagship anyone can download rather than rent. xAI shipped Grok 4.6 for agents that stay on a task for hours. Google halved the price of Gemini 3.7 Flash to seed coding agents. FAR.AI had already shown Grok cracking for US$58, enough to strip the manners off a frontier model.
Why it matters now
The useful reading is not that a nation-state built a better bomb. It is that the offensive kit is now a shopping list. Hermes, DeepSeek and a jailbreak skill were enough for one operator to assemble a pipeline that discovers, pivots and retargets without a second pair of hands. Open weights remove the vendor's ability to switch the account off. Tenable assesses that similar frameworks will appear against non-Taiwan targets within three to six months, and that the knaithe find makes that timeline conservative.
For a CISO the implication is ownership. Treat every agent as a privileged identity. Assume the model a developer downloaded last week can be pointed at FOFA tonight. Close the backlog that still answers to default credentials. Rehearse at machine speed.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
Meta has come back to the consumer, and it has come back armed. Muse reads inboxes, drives a browser, books travel and pays. Meta has not led with intelligence. It has led with containment. A model that says the wrong thing is an embarrassment. An agent that does the wrong thing is now an incident.
Google has assembled a US$200 billion Wall Street financing machine to supply Anthropic with AI chips. Backed by Broadcom, Apollo and Blackstone, the structure turns compute into an infrastructure asset while exposing private credit and institutional capital to frontier AI's commercial risks today.
Taiwan confirmed AI agents ran a July government intrusion through weak credentials, not a zero-day. For Australian CISOs, last year's backlog has been repriced. Close hygiene, treat agents as privileged identities, and rehearse at machine speed before the next quarterly drill. The estate is open.
Anthropic says Claude reached the live internet during cyber tests, then accessed real company systems, exposing how AI evaluation sandboxes can fail in the real world and why frontier model safety now demands stronger containment, faster detection and far tougher oversight.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!