Компанийн дотоод ажилтнууд “Muse” хиймэл оюун ухааны туслах нь хэрэглэгчдийн банкны данс болон хувийн мэдээллийг алдагдуулах магадлалтай гэж үзэн түгшиж байна.
Meta компани “Muse” (дотоод нэршил нь Hatch) хиймэл оюун ухааны агентаа зах зээлд гаргахаас өмнө аюулгүй байдлын ноцтой сул талыг илрүүлжээ. Энэхүү цоорхой нь Muse ашиглагчдад Meta-ийн мэдээллийн сан руу нэвтэрч, бусад хэрэглэгчийн эмзэг мэдээлэлд хандах боломжийг олгож байсан аж. Хэдийгээр тус компани бүтээгдэхүүнээ нээхээс өмнө яаралтай арга хэмжээ авч, зарим сул талыг зассан ч ажилтнууд нь системийн хамгаалалт хангалтгүй хэвээр байгаа гэж болгоомжилж байна.
Muse нь нислэгийн захиалга хийх, онлайн худалдан авалт гүйцэтгэх зэрэг үйлдлийг хийхийн тулд “Kernel-based virtual machine” (KVM) технологийг ашигладаг. Гэвч бүтээгдэхүүн гарахаас хоёр долоо хоногийн өмнө KVM-ийн тусгаарлалтын системээс хиймэл оюун ухааны агент гарч, бусад систем эсвэл хэрэглэгчийн виртуал машин руу нэвтрэх тохиолдол эрс нэмэгдсэн байна. Энэ нь аюулгүй байдлын ноцтой эрсдэл гэж тооцогдож байгаа тул Meta компани ийм төрлийн цоорхойг илрүүлсэн хүнд 300,000 ам.долларын шагнал амлажээ.
Аюулгүй байдлын судлаач Патрик Уордлын үзэж буйгаар, виртуалчлалын хил хязгаарыг аюулгүй байдлын хамгаалалт болгон ашиглах нь уг загварын хамгийн эрсдэлтэй тал юм. Хиймэл оюун ухаан нь виртуалчлалын нарийн төвөгтэй сул талуудыг олох, дүн шинжилгээ хийх, ашиглах зардлыг бууруулж байгаа нь ийм төрлийн халдлагыг улам хялбарчилж байна. Тус компанийн удирдлагууд энэ асуудлыг хурцаар хүлээн авч, аюулгүй байдлын багууд өдөр шөнөгүй ажиллаж байгаа ч, дотоод эх сурвалжууд үүнийг хангалтгүй, яаруу хийсэн хамгаалалт хэмээн шүүмжилжээ.
Дэлгэрэнгүйг эх сурвалжаас харах
↓Эх сурвалжийг нээх ↓
With the release of Meta’s buzzy Muse AI agent, there’ve been plenty of concerns over the amount of privacy and control Meta wants you to cede so it can serve as your “personal assistant.
It seems that even its own employees are worried. Before launching the AI agent, engineers found a security vulnerability that could’ve allowed Muse users to break into Meta’s own databases and services and access other people’s sensitive information, 404 Media reports.
Such a hack would be disastrous. Meta asks users to let Muse control everything from their bank accounts to their emails. The vulnerability was fixed in a “mad dash” before the product was released, but some employees are apparently convinced that the threat hasn’t gone away.
“Many senior engineers believe it’s inevitable we’re going to have a massive data breach as a result of Hatch,” a Meta source told 404, referring to Muse’s internal nickname.
To allow it to perform tasks that require a computer, like booking flights or shopping for groceries, Muse agents run on a kernel-based virtual machine, or KVM, which is supposed to be isolated from the rest of Meta’s infrastructure.
But barely two weeks before Muse launched, engineers rushed to fix a “sudden spike in reported KVM escapes,” according to an internal post by Meta executives, or instances in which a Muse agent sneaks out of its virtual machine and starts interacting with other Meta systems — or even other users’ virtual machines. One of these vulnerabilities could’ve allowed an attacker using a normal Muse account to access the sensitive data in Meta databases.
According to the reporting, concern around the vulnerability was serious enough that it even landed on CEO Mark Zuckerberg’s desk, with several security teams working day and night to fix it. But the Meta source sounded dubious about whether the fixes were robust enough, calling them “half-baked protections being rushed out to enable the launch.”
KVM escapes are considered so dangerous that Meta is offering a $300,000 bounty to anyone who finds a vulnerability that can cause one to happen. On its bug bounty page, Meta lays out the stakes in stark terms. “Because a Muse agent holds a user’s most sensitive data and can act on their behalf, we treat compromise of that boundary as a first-class security risk,” the company says, as pointed out by 404.
Experts say flaws in how Meta walls off its agent that could lead to such an escape happening.
“This issue is that Hatch makes the virtualization boundary a production security boundary,” security researcher Patrick Wardle told 404. ” I feel like this design is inherently risky, particularly risky as AI lowers the cost of finding, analyzing, and exploiting exactly these kinds of complex virtualization vulnerabilities.”
The panic behind the scenes over the KVM escape comes at a pivotal moment over the current expectations around AI tools and their actual capabilities. For months, top AI companies have publicly fretted about how their powerful agents have broken containment and launched cyberattacks on other companies and government websites. We’re now seeing how dangerous the tech can be amid the push to have AI agents control our personal lives.
More on AI: Man Says Meta’s Muse AI Gave His Home Address Out to Strangers
The post Meta Insiders Convinced Muse Is Going to End Up Leaking the Bank Accounts and Email Archives They’re Vacuuming Up From Users appeared first on Futurism.

