Decoding the world of cybersecurity

Meta Muse AI agent appears as ordinary browser traffic, Cequence research finds

Cequence observed traffic matching Meta’s Muse at more than half its sampled customers, including authenticated account activity that conventional browser checks could not distinguish from human use.

Meta Muse AI agent appears as ordinary browser traffic, Cequence research finds
Summary
  • Cequence tracked Muse-like traffic between 1 and 24 September.
  • Observed agents used real browsers and could complete multi-factor authenticated sessions.
  • The vendor’s sample does not establish the share of all European businesses affected.

Automated browsing by Meta’s Muse agent appeared in traffic at more than half the organisations examined by Cequence Security, according to research released on 7 October that challenges the assumptions behind conventional browser and customer authentication checks.

Cequence studied traffic from 1 to 24 September across customers in financial services, travel, retail, software and other sectors. It says Muse generally presented as a normal Chrome browser rather than declaring itself an automated agent, requiring behavioural analysis to distinguish the activity from human-operated browsing.

The company reported nearly sixfold growth in matching traffic at the median customer over approximately two weeks after first appearance. This figure describes the sample Cequence studied, not a verified measure of Muse adoption across all organisations or countries.

The observed agent used a cloud-hosted browser controlled by an AI model and routed connections through consumer VPN services. Unlike a conventional software integration that declares a machine identity through a dedicated API or signed request, the activity resembled a normal consumer session.

At financial institutions in the sample, Cequence says it observed successful account sign-ins that completed multi-factor authentication on the user’s behalf. A successful login establishes that the relevant authentication checks were satisfied, but it does not reveal whether the person or an authorised automation completed the interaction.

Cequence also observed shopping journeys in which agents compared options, populated baskets and sometimes completed purchases. That behaviour blurs the operational distinction between a scraper and a customer-authorised assistant, because both can generate automated traffic to the same pages.

The vendor introduced Agent Trust alongside the research, describing controls that identify agent activity and assess individual requests. Claims about its effectiveness should be distinguished from independent proof that the product detects every undeclared agent or prevents account misuse.

The emergence of these interactions presents an application security issue rather than simply a question of blocking bots. Organisations may wish to permit customers to use authorised assistants while separately identifying anomalous requests, unexpected account changes or unusually extensive data collection.

Agent identity standards, transaction authorisation and behavioural detection address different aspects of the problem. An agent may be genuinely acting for a customer yet attempt an action beyond the customer’s intention, while an attacker could misuse a stolen credential to mimic authorised automation.

Cequence described a travel-sector customer that blocked almost one in five requests attributed to Muse late in September while permitting the rest. The intervention was made at request level, which illustrates a distinction between stopping a specific anomalous action and denying access to every automated visitor.

At the median organisation in Cequence’s monitored population, traffic matching Muse increased almost sixfold during roughly two weeks of observation. The company said browser-version changes occurred in a coordinated manner across sessions, which informed its behavioural classification. Such a signature can be useful for detection but does not establish the intentions of an individual customer or agent.

Meta’s browser-based agent can interact with familiar login and checkout processes using the authority delegated by its user. The financial-sector examples reported by Cequence involved successful multifactor authentication, not proof that authentication had been technically bypassed. Whether a subsequent action is authorised depends on its scope and the account holder’s instructions.

The sample covered financial services, retail, travel, software and other industries, without a published country-by-country breakdown. It consequently supports a finding about traffic among Cequence customers, but not a numerical claim about the share of European sites receiving Muse requests. The company’s launch of Agent Trust is a commercial response to those observed behaviours rather than an independent validation of its detection accuracy.

The associated product launch creates another evidential boundary. Cequence’s research can be reported as a vendor observation, while claims about its new product’s effectiveness remain supplier assertions until supported by independent operational evaluation. The wider identity problem is real regardless of which detection product an organisation selects.

×