Teradata, Darktrace and Barracuda Roll Out AI Controls as Meta Muse Flaw Exposes Agent Risk
Teradata, Darktrace and Barracuda unveiled new controls for enterprise AI on Sept. 22, 2026, while TechRadar reported a zero-day in Meta's Muse assistant that can hijack tokens and expose data from connected apps.
TechRadar reported that Patrick Wardle, founder of the nonprofit Objective-See, named the flaw not-a-mused. Exploiting it requires three conditions: local access to an already compromised device, voice dictation enabled in Muse, and Muse connected to productivity apps such as email, WhatsApp, calendar or social media. The bug is in an undocumented setting called endo_voyager_dictation_endpoint, which changes the endpoint that receives dictated commands. Voice commands are normally processed in the cloud, where Meta can log them; an attacker with local access can redirect them to attacker-controlled infrastructure. The assistant then sends its authentication token with the instructions, allowing the attacker to seize the token and prompt the AI tool to pull sensitive data from connected apps. Wardle described the vulnerability as combining data exfiltration and privilege escalation.
"We can manipulate the agent and leverage its privileges to do whatever we want," Wardle told Ars Technica, according to TechRadar. "So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself." He said he built proof-of-concept attacks that wrote malicious files to disk and took pictures, in many cases without alerting users. Meta has been informed but has not commented or issued a patch, TechRadar reported. Muse is available for Mac, and Meta describes it as able to book appointments, fill out forms, handle customer service, make purchases, generate images and create documents.
The flaw adds to warnings about the broad permissions AI assistants require. TechRadar noted that hidden prompts in phishing emails have tricked agents into exfiltrating PDF documents, and early agentic AI assistants were reported to have deleted users' inboxes.
SiliconANGLE reported that Darktrace Holdings made SECURE AI generally available, applying its behavioral detection to corporate AI tools and agents. Telemetry from about 8,200 Darktrace deployments showed more than 80% of monitored customer accounts used generative AI services in August, and the average organization used five different AI providers that month. Early customer cases included one company where most employees used unauthorized AI services despite a single approved assistant, another where nearly 90 AI agents were built in a low-code environment without an approval process, and a third where contractors' unmanaged use of several AI platforms triggered an immediate legal review.
SECURE AI integrates with AWS, Anthropic, Microsoft and OpenAI. It scans sessions in ChatGPT Enterprise, Claude, Microsoft Copilot and Amazon Bedrock in real time for jailbreak attempts, sensitive data exposure and indirect prompt injection, ranking each session by risk. Shadow AI detection uses secure access service edge integrations such as Microsoft Entra Global Secure Access; administrators can block unsanctioned services or quarantine devices. Companies can upload their AI policies in free-form text and have the software check them against regulatory and compliance frameworks. Darktrace maps AI agents to the humans behind them and records what each agent can reach, extending coverage into development environments such as Amazon Bedrock and Microsoft Copilot Studio to catch excessive permissions and misconfigurations before deployment.
Ed Jennings, who became Darktrace's president and chief executive in March, said the security industry spent two decades cataloging known threats. "AI breaks that model," he said, adding that the important signal is when something "starts behaving differently from what is normal for the organization." Darktrace is a member of OpenAI's Daybreak Defense Network and is developing capabilities that pair OpenAI's Daybreak models with its own behavioral data. McCall McIntyre, head of global cyber partnerships at OpenAI, said working with partners such as Darktrace is "critical to translating advances in AI into stronger, practical defenses." SECURE AI, announced in February, is on sale now as a standalone product or as part of the Darktrace Behavioral Defense Platform, including through AWS Marketplace and Microsoft Marketplace.
SiliconANGLE reported that Barracuda Networks launched Barracuda AI Data Security, which monitors and controls what company data employees send to AI tools. The company is targeting smaller businesses and managed service providers, saying most governance tools are built for large enterprises. Detection is handled by Barracuda IQ, and the product runs on the BarracudaONE platform with default sensitive-data blocking active from deployment. It covers ChatGPT, Microsoft Copilot and Gemini, and Barracuda said the engine can apply policy across more than 1,300 generative AI services. Prebuilt detectors scan prompts and uploads for customer records, passwords, financial data and proprietary source code, blocking them before they reach an outside model.
The product also flags prompt injection, jailbreak attempts, hate speech and topics an employer has ruled out, with detection aligned to the OWASP Top 10 for large language model applications. Every AI interaction is recorded in an audit log that can be exported in one click for auditors and insurers. Policies can be set per team, per tool and per data type through firewall-style rule screens, and Barracuda's Bailey assistant guides administrators through custom rules. Managed service providers get multitenant management and can bundle pricing into existing service packages. Neal Bradbury, Barracuda's chief product officer, said AI adoption is accelerating faster than most businesses can keep pace, creating one of the most urgent security and compliance challenges organizations face today. A Barracuda survey of 2,000 IT and security decision-makers found that 49% of CIOs at companies with 500 to 1,000 employees said their teams lack the skills to secure and govern AI already in use; across all respondents, the figure was 38%. Geoff Turner, chief executive of managed service provider Elevate Technology Group, said customer AI policy "only goes so far" and his firm needs controls that are "simple, scalable and built for real-world environments." Barracuda AI Data Security becomes available in October and is included at no additional cost in Barracuda SecureEdge Premium Access.
SiliconANGLE reported that Teradata expanded its Tera AI assistant with a context engine and execution system designed for governed agents that carry out data tasks across enterprise systems. Tera is an agentic AI workspace and natural-language interface that lets users interact with enterprise data and AI agents without writing SQL or code. The new Tera Context Engine connects information from databases, catalogs, pipelines and other sources without requiring companies to move data. It brings together metadata, data lineage, business definitions and access policies so an agent can interpret a request in the context of the organization, and it can trace AI outputs back to their sources while applying the same policies as information moves between systems.
A feature called Tera Harness handles execution by selecting the tools, models and data needed for a task, tracking progress across multiple steps and pausing for human approval before sensitive actions. It can resume work after an infrastructure failure and applies controls before an action runs. Agent Skills packages common data engineering, analysis and data science tasks into reusable functions for writing SQL or Python, optimizing queries, tuning workloads and sizing compute resources. Organizations can connect their own tools through the Model Context Protocol. Teradata said that in company-reported testing on the SWE-bench Pro benchmark using the same Opus 5 model, Tera used 73% fewer tokens than Claude Code, completed tasks 42% faster and had 58% lower total cost, while achieving a higher task completion rate. On the data-eng-bench pipeline engineering benchmark, Teradata reported a 53% lower cost per reliably solved task than Snowflake's Cortex Code, based on Snowflake's published results. The company cautioned that the comparisons reflect its testing and stated benchmark conditions, not performance across all enterprise workloads.
"Most enterprises are not starting from scratch with AI. They are dealing with tools that do not work together and a skills gap that makes those tools hard to use at scale," said Sumeet Arora, Teradata's chief product officer. Teradata said customers can choose their models and run workloads in cloud, on-premises or sovereign environments. It is offering AI Services to help customers identify use cases, configure Industry Knowledge Models and move enterprise knowledge into production. The new capabilities and specialized agent skills will be available in the fourth quarter of 2026.