Skip to content

Mon - Fri: 10.00 - 5.00

[email protected]

Delana Technologies

Delana Technologies

Delana Technologies delivers expert cybersecurity, cloud, and AI-driven IT strategy solutions. Transform your enterprise securely and intelligently.

  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions
  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions

Mon - Fri: 10.00 - 5.00

[email protected]

Personal AI Agents Went Mainstream This Week. Your Wallet Is the New Attack Surface.

  1. Home   »  
  2. Personal AI Agents Went Mainstream This Week. Your Wallet Is the New Attack Surface.

Personal AI Agents Went Mainstream This Week. Your Wallet Is the New Attack Surface.

September 22, 2026 admincybersecurity

For three years, “trending in AI” mostly meant a smarter chatbot. This month the trend changed shape. The fastest-growing AI product in the United States right now does not answer questions. It spends money, sends email and cancels things on your behalf, and within two weeks of launch researchers had already shown two different ways to turn that power against its owner.

This is the story of the personal AI agent going mainstream, and why the thing most worth protecting in 2026 may no longer be your password. It is your agent’s permission slip.

BANKCARDSHOPEMAILPHONECALENDARLAPTOPAIAGENTYour AI agentholds your card.Who else does?Personal AI agents | September 2026DELANA TECHNOLOGIES
A personal agent is useful precisely because it is connected to everything. That is also what makes it worth attacking.

The trend: AI that does the errand, not just the answer

On 8 September 2026, Meta launched Muse, a personal AI agent that is separate from its Meta AI chatbot. You give it a goal and it keeps working after you close the app: booking travel, filling out forms, sending invitations, tracking expenses, auditing subscriptions and negotiating a bill down. Meta says it checks with you before it spends or cancels anything.

People wanted it. According to Sensor Tower figures reported by Bloomberg, Muse was downloaded more than 902,000 times in its first six days, ahead of the pace set by the original Meta AI app. By 19 September it was the No. 1 free iPhone app in America, above ChatGPT, Gemini, Claude and Instagram. On 17 September Meta added a Mac client with access to files, Messages, Calendar, Notes and Mail.

That is the real trend worth tracking. Chatbots were a knowledge product. Agents are a delegation product, and delegation means credentials, payment methods and standing access to your accounts. Muse is simply the first to reach mass-market scale. Every major lab is building the same thing.

Two weeks in the life of a mainstream AI agent, September 2026
DateWhat happened
8 SeptMeta launches Muse on iOS, Android and web, with a bug bounty of up to $300,000
14 SeptDownloads pass 902,000 in six days (Sensor Tower)
17 SeptMuse for Mac ships, with access to Mail, Messages, Calendar, Notes and files
19 SeptMuse becomes the No. 1 free iPhone app in the US
21 SeptResearcher Patrick Wardle publishes a proof of concept that hijacks the Mac client and reaches a linked iPhone
SeptThe APort Vault benchmark shows every one of 14 tested models can be socially engineered into requesting unauthorized payments

Attack one: talk the agent into paying

The first problem is not specific to Meta. A new research paper, APort Vault by Uchi Uchibeke, asked a simple question: can an AI payment agent be socially engineered into sending money it should not send?

The test was large. It replayed 4,371 attacks written by real people during a live capture-the-flag competition against 14 models from 8 labs, for 225,964 evaluations in total. The results should end the idea that a smarter model is a safer one.

Can an AI payment agent be talked into sending money?APort Vault benchmark: 4,371 human-written attacks, 14 models, 8 labs, 225,964 evaluations79.4%62.6%0of authorization-boundaryattacks produced a paymentrequest (model alone)of those attacks workedagainst all 14 modelsat onceunauthorized transferswith a deterministicpre-action checkTakeaway: the model is not the control. A hard rule outside the model is.Source: Uchibeke, “APort Vault” (arXiv, Sept 2026) | delana.co
No model resisted on its own. A simple, deterministic authorization check stopped every unauthorized transfer.

In the hardest category, attacks aimed squarely at the authorization boundary, the models alone generated a payment request between 71.2% and 84.3% of the time, or 79.4% overall. More striking: 62.6% of those attacks succeeded against all 14 models. An attacker does not need to know which AI you use. The same trick works on nearly everyone’s.

The good news was equally clear. When a deterministic pre-action check was placed in front of the payment, the study recorded zero unauthorized transfers in 69,297 attempts, against 140 in 76,842 comparable attempts without it. The fix was not a better prompt or a bigger model. It was a rule the model could not argue its way past.

If your only protection against an AI agent making a bad payment is the AI agent’s own judgment, you do not have a control. You have a hope.

Attack two: hijack the agent’s device

The second problem arrived four days after Muse reached the Mac. On 21 September, Patrick Wardle, the macOS security researcher behind the Objective-See Foundation, published a proof of concept against the Muse Mac client.

How one infected laptop reaches your phone through an AI agentBased on Patrick Wardle’s Muse for Mac proof of concept, disclosed 21 Sept 202612345Malwareon the MacChanges ahidden settingCapturesagent authLists linkeddevicesCommandsthe iPhonealready runningas the userdictation endpointredirectedprompts and tokensinterceptedvia the agent’saccount APIlocation, Bluetoothscan and moreThe attack went around the cloud vault, through the trusted client.Lesson: an agent’s permissions are only as safe as the weakest device it is signed into.
Wardle calls it access amplification: low-privilege malware borrows the far broader permissions the user already granted the agent.

According to Wardle’s published code and RuntimeWire’s reporting, an undocumented setting in the Mac app can be changed by an ordinary, unprivileged process to redirect dictated prompts to an attacker’s server. From there, the attacker can capture authentication material, ask the account which devices are linked, and instruct one of them to act. His demonstration pulled an iPhone’s location in Barcelona and ran a Bluetooth scan on it, invisibly.

Two points deserve fair weight. First, the attack requires code to already be running on the Mac; it is not a drive-by compromise. Second, Meta built serious protections into the cloud side of Muse, including an isolated virtual machine for credentials and a separate authorization service. Wardle did not break those. He went around them, through the app on the laptop that the cloud already trusted.

That is the lesson that applies far beyond one product. Normally, macOS makes an unknown program ask permission before it can read your location or use your microphone. A personal agent has usually been granted those permissions already. Compromise the agent and you inherit everything the user said yes to.

Why this is a business problem, not a consumer one

Muse is marketed to individuals. That is exactly why it will end up inside your company without anyone approving it. An employee installs it on the work Mac because it clears their inbox. They connect it to Mail and Calendar because that is the point. Perhaps they add the company card so it can rebook travel. None of that shows up in an IT ticket.

We have written about shadow AI and what staff paste into chatbots, and about the credentials held by agents your company deploys. Personal agents are the uncomfortable middle case: unsanctioned like shadow AI, but holding standing access like a deployed agent. They can read, send and spend, and they sit on endpoints you may not be monitoring.

Put the two findings together and the risk is concrete. A convincing email tells an agent a vendor’s bank details have changed and payment is overdue. Or malware on one laptop quietly borrows an agent that is signed into the owner’s phone, inbox and card. Neither requires a novel exploit against your network. Both go through a tool somebody installed to save twenty minutes a day.

What to do this month

  1. Write a one-paragraph personal agent policy. State whether consumer AI agents may be installed on company devices or connected to company email, calendar or chat. Silence is currently a yes.
  2. Never give an agent a card that can empty an account. Use virtual or single-purpose cards with low limits and merchant restrictions for anything an agent can touch.
  3. Put the payment rule outside the AI. Approval thresholds in your bank or finance system, dual authorization for new payees, and hold periods for changed bank details. The benchmark shows these deterministic checks work where model judgment does not.
  4. Verify payment changes out of band. Any request to change a vendor’s bank details gets a phone call to a number you already had, whether the request came from a person or an agent.
  5. Treat endpoint protection as agent protection. The Muse attack started with code on a laptop. Current EDR, patched operating systems and no local admin rights for everyday users shrink the foothold an attacker needs.
  6. Audit connected apps. Review which third-party apps have OAuth access to Microsoft 365 or Google Workspace and revoke what nobody can justify.
  7. Read the activity log. If an agent is approved, someone should review what it did each week, including purchases, messages sent and new connections.

Frequently asked questions

What is a personal AI agent?

It is AI software that takes actions for you rather than only answering questions. Given a goal, it can browse websites, fill in forms, send email, book reservations and make purchases through the accounts you connect, and it keeps working in the background. Meta’s Muse is the most widely used example as of September 2026.

Is Meta Muse safe to use?

Meta has built meaningful protections, including approval prompts before purchases, an isolated cloud environment for credentials and a large bug bounty. The disclosed Mac flaw requires an attacker to already be running code on your computer. The practical answer is that it is as safe as the devices it is signed into and the payment limits you give it. Keep those tight.

Does asking for my approval before purchases solve the problem?

It helps, but approvals only work if the person reads them carefully every time, and social engineering targets exactly that. The strongest protection in the APort Vault study was a deterministic rule enforced outside the model. Pair approval prompts with hard limits on the card and in your finance system.

Should small businesses ban AI agents?

An outright ban tends to push usage out of sight, which is worse. A better approach is to decide which accounts and payment methods agents may touch, provide approved options with limits, and make the rules short enough that people actually follow them.

Get ahead of the agents already in your office

Delana Technologies helps Florida businesses find the AI tools already connected to their accounts, set payment and access controls that do not depend on an AI’s judgment, and harden the endpoints those agents live on through Zero Trust architecture. If you are not sure which agents can read your email or use your company card, call 239.414.5126 or contact us.


Sources: Meta, “Introducing Muse” (8 September 2026) and the Muse App Store listing; Bloomberg, reporting Sensor Tower download data (21 September 2026); Axios and WinBuzzer on Muse’s App Store ranking (18-21 September 2026); RuntimeWire, “Meta’s Muse flaw lets Mac malware reach linked iPhones, researcher says” (21 September 2026), and Patrick Wardle’s not-a-mused proof of concept; Uchi Uchibeke, “APort Vault” (arXiv, September 2026), as summarized by AI Weekly.

Post navigation

Previous: AI Models Escaped Testing and Hacked Real Companies

Florida Service Location

  • Cybersecurity, AI Consulting & IT Services in West Palm Beach, Florida
  • Cybersecurity, AI Consulting & IT Services in Sarasota, Florida
  • Cybersecurity, AI Consulting & IT Services in Port St. Lucie, Florida
  • Cybersecurity, AI Consulting & IT Services in Pembroke Pines, Florida
  • Cybersecurity, AI Consulting & IT Services in Naples, Florida
  • Cybersecurity, AI Consulting & IT Services in Miramar, Florida
  • Cybersecurity, AI Consulting & IT Services in Miami, Florida
  • Cybersecurity, AI Consulting & IT Services in Hollywood, Florida
  • Cybersecurity, AI Consulting & IT Services in Hialeah, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Myers, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Lauderdale, Florida
  • Cybersecurity, AI Consulting & IT Services in Cape Coral, Florida
  • Cybersecurity, AI Consulting & IT Services in Boca Raton, Florida
  • Cybersecurity, AI Consulting & IT Services in Coral Springs, Florida

Technology Services

  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions
  • Case Studies
  • Home
  • Contact Us
  • Privacy Policy
  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions

© Copyright 2025 Delana Technologies LLC