Home · Technology · Oct 6 archive

Meta Patches Muse Security Flaw Hours After Report

Confirmed

Technology Desk

In Short: GitLab released patches to address multiple flaws, including a maximum-severity security vulnerability that saw probes within hours of public disclosure.

Meta's Urgent Patch: Muse 'VM Escape' Vulnerability Exposed!|2026.10.06|@OrangeAINEWS
YouTube — Orange Tech NEWS

Security researchers at Hacktron AI used Anthropic's Claude Opus 5 to weaponize a libheif image-processing bug, breaching an OpenAI employee's ChatGPT account and reaching OpenAI's internal GitHub environment within 72 hours.

Organizations running self-managed GitLab instances exposed to the internet must apply the patches immediately or limit public access, GitLab advised.

YouTube — Orange Tech NEWS YouTube

The Wall Street Journal confirmed the breach, and both Discourse and OpenAI have since patched the underlying flaws.

Ethiopia announced it was closing its embassy in Eritrea and ordered 10 Eritrean diplomats to leave within 48 hours, accusing them of threatening national security.

Hours earlier, Ethiopia's National Intelligence and Security Service imposed an indefinite ban on drone flights over Addis Ababa, citing the need to protect officials and infrastructure.

In Brazil, thousands of right-wing demonstrators occupied government buildings in Brasília, ransacking offices and trashing the Congress hall before police regained control.

Lula accused Bolsonaro of encouraging the coup by “fascist fanatics” and issued a decree directing the federal government to take control of security in the capital.

Detainees at a now-closed immigrant detention center in Florida were held in small metal enclosures for up to two hours, a practice deemed inhumane by the Department of Homeland Security’s Inspector General.

The exploitability of a Muse security flaw remains contested, with Meta releasing a hot-fix within 24 hours of its disclosure.

Amazon blocked Muse shopping 12 hours before the flaw's public disclosure, indicating some entities had already identified the risk.

Security teams still cannot see what Muse accesses, highlighting ongoing concerns about the application’s behavior.

What this adds

The Muse security flaw's exploitability is still under debate, with some experts noting it requires malicious code already running on the user's machine.

What's confirmed

What's still developing

Sources