SIGNAL
Monitoring active

AI Threat Briefing

The top 3 verified AI security incidents from the last 2 days β€” ranked and summarized automatically.

Edition 2026-09-23 Window 2d Generated 2026-09-23 05:02 UTC
High news
AI Security Cross-Industry

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is

Read full report β†’
Notable news
AI Security Cross-Industry

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21. It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta.

Read full report β†’

Stay in the loop

Have feedback or a story we missed? Write to security@korelex.ai

Get this in your inbox

Free daily briefing, delivered every morning.