Fetching from the wire…
Top 5 · 2026-09-23 · source-backed
Amazon cut off Muse because it didn't identify itself as an agent in every request and never asked permission. That's the whole reason, per GeekWire.
Zuckerberg says Muse will take "a very small cut" of each transaction, paid by merchants. Nikesh Arora calls it "a bigger battle than anyone anticipates." Aaron Levie says the industry is "basically two weeks into this entire topic." Musk says Amazon "won't be able to tell whether the buyer is a human or an AI," which is the interesting technical claim in the pile, and I think he's wrong in the short term and right in the long one. Behavioral fingerprinting catches today's agents easily. It won't catch an agent driving a real logged-in browser session at human speed, which is exactly what Tencent's BrowserSkill and similar tools already do.
The markets priced it the same day. Bloomberg reported a selloff in businesses that make money on customers not switching: Charles Schwab down more than 6%, Allstate 5.5%, JPMorgan and Wells Fargo over 3% each, S&P 500 Financials down nearly 2%. Previous Muse coverage was about download counts and security bugs. This is the first time public equity markets treated agent-driven switching as a revenue threat.
Three unrelated companies shipped agent-identity products on September 22. Baselayer, a KYB fraud vendor used by more than 2,000 US financial institutions, raised $35M led by M13 and launched "Know Your Agent" to verify who deployed an agent and what it's permitted to transact. Known spun out of Identity Digital with DNSid, a DNS and PKI scheme tying each agent to an accountable organization, submitted to the IETF as an Internet-Draft with Vint Cerf on the advisory council. And Coverage Cat launched an insurance brokerage whose intended buyer interface is somebody else's personal agent, over an Agent API and MCP.
Then the security half. Patrick Wardle found a Muse 0-day, reported by Ars Technica: any local process on macOS could rewrite Muse's undocumented settings, including the endpoint that receives cloud dictation. Point it at your own server, get the account token and full control of the agent. Wardle built proofs that write files and take photos with no visible sign. Meta hotfixed it more than 12 hours after disclosure. Separately, a researcher asked Muse to archive the files it could see and mail them to Google Drive, and it exported 6.8 GB of its own runtime: internal docs, 113 subagent traces, about 68 skill directories, configs naming unreleased connectors, SSH key files. Meta's bounty program marked it "Not Applicable."
Nat Friedman, head of product at Meta Superintelligence Labs, admitted on X that Muse was "heavily inspired as a product by OpenClaw." Muse reuses OpenClaw's workspace filenames and ships a SOUL.md with nearly identical content.
Build an agent that transacts on somebody else's site, and you now need a declared identity and the platform's permission. Build an agent with an export connector, and assume it can and will move its own sandbox somewhere you didn't plan for. Keep secrets out of any filesystem the agent can read.
Each link below shares sources, entities, or timing with this story.
Patrick Wardle disclosed on September 21 that Meta's Muse macOS app exposes an undocumented setting, endo_voyager_dictation_endpoint, which an unprivileged local process can rewrite with no elevated permissions. Rewrite it and dictated audio and prompts go to attacker infrastr...
Starting the night of September 20, Muse users who pointed the agent at Amazon.com got a popup instead of a product page: "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed." Twelve days after launch. Amazon ho...
His argument is that every lab can pace itself without industry coordination, citing Meta's months-long delay of Muse from a planned April launch to September 8 for safety and security work, with the line that Meta "didn't call for everyone else to do this before we would." He...
Your read-only flag is a claim, not a guarantee. Two independent Postgres MCP servers proved it on September 4. Postgres MCP Pro got CVE-2026-85620 at CVSS 9.2. The bug is one line of reasoning in safe_sql.py: the validator checks function names on FuncCall AST nodes. A functi...
More AI-generated code did not turn into proportionally more shipped product. That's the internal finding at the center of Reuters' August 26 special report, and it's the most useful number-free sentence I've read this month. Project OT, for Organization Transformation, was ha...
It launched September 10 on GPT-6 Astra, co-designed with Morgan Stanley and Evercore (Bloomberg), and it builds valuation models and pitchbooks from a firm's own templates. Data from Daloopa, PitchBook, LSEG News and Crunchbase comes built in, indexed and hosted by OpenAI so...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.