> daily_signal(2026_07_08)

Meta's new Muse AI can put your face in someone else's AI photo — on by default, no notification, ever — while a Russian phishing crew we've tracked for a week gets a $10 million bounty.

PickBits Daily Signal · Wednesday, July 8, 2026

By Mark Pickering · 10 min read · July 8, 2026

// tl;dr

Meta had a rough month before today even started. We watched a dormant facial-recognition tool surface on fifty million phones, then an AI chatbot bug that let attackers hijack real Instagram accounts, and now Muse Image ships with your public photos fair game for anyone's prompt — no consent required, unless you find the toggle yourself. That's the privacy story today. The threat side moved too: the Russian social-engineering campaign against Signal and WhatsApp that we first flagged when Ukraine's security service blew the whistle on July 2 now has a ten-million-dollar bounty attached, official confirmation of a threat that's been live since March. And underneath both, Apollo's chief economist put a number on something a lot of people have been feeling but not measuring: outside seven companies, AI hasn't moved profit margins yet, and Wall Street is pricing in years of gains that may not land until 2029. Three different stories, one shared question none of them answer cleanly: who's actually accountable when the thing moving fast stays invisible until it isn't.

A default setting, a bounty, and a chart all landed the same message this week: check what you assumed was already handled.

1. Meta's Muse Image opts every public Instagram account into AI face-remixing, with no consent and no notification, ever.

A photo you posted for your friends just became material for a stranger's prompt.

Meta launched Muse Image on July 7. It's the first in-house AI image generator from Meta Superintelligence Labs, built to compete with OpenAI's GPT Images 2.0 and Google's Nano Banana 2. It's live now inside the Meta AI app, Instagram Stories, and WhatsApp, with deep integration into Instagram specifically. Tag any public account in a prompt, and Muse can pull that person's own photos to generate a new image using their likeness. No request goes out. No consent is asked. Meta's own help center confirms it: the person whose face was used will not be notified, under any circumstance.

The setting exists to turn off, but Meta buried it three menus deep: open Instagram, tap the three lines top right, scroll to Sharing and reuse, and toggle off both Posts and Reels. Even then, the fix only applies going forward. Anything already generated using your face stays out there, permanently. This is Meta's third privacy misstep this month alone — after a dormant facial-recognition tool we found sitting quietly on fifty million phones, and an AI customer-support chatbot that let attackers hijack high-profile Instagram accounts just by asking it to change the account email. Ship first, let users discover the cost later, is starting to look less like an accident and more like a habit.

TechCrunch report July 7 2026 Meta launches Muse Image AI generator from Meta Superintelligence Labs live in Meta AI app Instagram Stories and WhatsApp public Instagram accounts opted in by default to AI likeness remixing no consent no notification opt-out buried in Sharing and reuse settings not retroactive
techcrunch.com · July 7, 2026
Why this matters: If you have a public Instagram account, your face is already fair game for someone else's AI prompt right now, today, whether or not you ever open the app to check. Action this week: open Instagram, tap the three lines top right, go to Sharing and reuse, and toggle off both Posts and Reels. It takes about ninety seconds. If you've already spotted an AI image made with your likeness without your knowledge, know the opt-out won't remove it; report it directly through Instagram's in-app reporting tools instead of waiting for Meta to flag it, because they won't. Share this with anyone in your family or friend group who keeps a public account. They're the ones this setting was quietly switched on for.

techcrunch.com: Meta rolls out Muse, a new AI image generator (July 7, 2026)
digitaltrends.com: Meta's new AI can generate images of you from your Instagram, and you're opted in (July 2026)

2. The US just put a $10 million bounty on the Russian hackers targeting Signal and WhatsApp backup keys — a campaign we've been tracking since July 2.

A text that looks like tech support is how a spy agency gets into your phone now.

The State Department's Rewards for Justice program is offering up to $10 million for information on two Russia-linked hacking groups, tracked as UNC5792 and UNC4221, tied respectively to the FSB and Russia's Border Guard Service and military intelligence. We flagged this campaign on July 2, when Ukraine's security service went public with a joint finding alongside the FBI; by July 3, the reward was already in motion. Today it's official, and the FBI filled in how the campaign actually works. It's social engineering, not a software exploit: fake "official support" texts, doctored Signal group-invite pages, and prompts asking a target to hand over a verification code, a PIN, or a backup recovery key.

The backup key is the real prize. Once an attacker has it, it stays valid even if the victim creates a brand-new account with the same phone number, meaning a single successful phish can grant access that survives someone's attempt to start fresh. The campaign has been running since at least March, targeting current and former US government officials, military personnel, political figures, and journalists — and it's not the first time we've seen Russian state hackers run exactly this profile of target. A 2017 case against two FSB officers, indicted for the Yahoo breach, named the identical combination: government officials and journalists, both. Different breach, years apart, same playbook.

The Record report July 2026 US State Department Rewards for Justice offers 10 million dollar reward for information on UNC5792 and UNC4221 Russian hacking groups linked to FSB Border Guard Service and military intelligence targeting Signal and WhatsApp backup recovery keys via social engineering campaign active since March 2026
therecord.media · July 2026
Why this matters: If you use Signal or WhatsApp for anything sensitive, this campaign is designed to look exactly like the app itself asking you a routine question, which is why it works. Action this week: never share a verification code, PIN, or backup recovery key with anyone who contacts you first, even if the message looks official — that's the entire method behind a $10 million bounty. If you recently followed a Signal group-invite link that asked you to re-verify or re-enter a backup key, treat the account as potentially compromised: regenerate your backup key from inside the app's own settings, never from a linked page, and re-register. Share this with anyone in your life who works in government, journalism, or advocacy. They're the exact target list.

therecord.media: US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp (July 2026)

3. Apollo's chief economist ran the numbers on AI's profit lift outside the "Magnificent Seven." It's zero.

The market bought a story before it checked whether the numbers agreed.

Torsten Slok, chief economist at Apollo Global Management, published a chart this week making a point Wall Street has mostly avoided saying out loud: at the roughly 493 S&P 500 companies outside the "Magnificent Seven" tech giants, there is no measurable AI-driven margin expansion yet. His argument is about timing, not whether AI works: regulated, process-heavy sectors, like healthcare, banking, energy, pharmaceuticals, and manufacturing, need years of compliance work and workflow redesign before productivity gains actually show up on a balance sheet, not months. Even where the gains are real, Slok notes, they're often too diffuse to be captured cleanly in standard financial reporting, which delays the point where investors can verify anything at all.

The stakes are in the timeline math. Slok's framing: if the productivity bump takes five years instead of five months, a lot of AI-premised stock valuations are due for a hard correction, with market expectations and actual earnings potentially diverging out through 2029. This lands against a backdrop we've been tracking all year: Anthropic's $965 billion valuation and confidential S-1 filing, Alphabet's gen-AI revenue up 800% year over year matching its capex line, hyperscalers stacking tens of billions into AI infrastructure. The market has, in fact, been pricing in a lot. Slok's chart is the first widely circulated attempt to check whether the other 493 companies are actually cashing that check yet.

The Decoder report July 7 2026 Apollo chief economist Torsten Slok chart showing zero AI profit margin lift at 493 non-Magnificent Seven S and P 500 companies regulated industries healthcare banking energy pharma manufacturing need years not months to capture AI productivity gains risk of valuation correction if timeline runs to 2029
the-decoder.com · July 7, 2026
Why this matters: If any part of your retirement account or portfolio is exposed to AI-adjacent stocks, this is a direct read on how much of that exposure is still a promise rather than a result. Action this week: check what fraction of your AI-adjacent holdings, directly or through an index or retirement fund, assumes near-term margin expansion in non-tech sectors rather than the seven companies already proving it works. If you work in a regulated industry evaluating AI ROI, use Slok's five-months-versus-five-years framing as a planning input: budget for the compliance and process-redesign work as the actual bottleneck, not the AI tooling itself, and don't expect the gains to show up on a standard quarterly cycle. Follow this one; it's going to keep resurfacing every earnings season until someone's numbers settle it.

the-decoder.com: Apollo economist warns AI profit gains outside tech could take well beyond what Wall Street expects (July 7, 2026)

4. Meta's brain-reading AI just closed most of the gap with a surgical implant — no scalpel required.

The distance between a research lab and a working voice just got a lot shorter.

Meta's FAIR research team published Brain2Qwerty v2, a model that reconstructs full sentences from brain activity recorded entirely outside the skull, using magnetoencephalography to pick up the magnetic fields the brain's motor cortex gives off during intended typing. No implant, no surgery. Nine volunteers wore the sensor for ten hours each, silently mouthing out sentences on a keyboard they couldn't see, and the model learned to reconstruct what they meant to type from the signal alone. The average word error rate dropped to 39%, down from 55% for the raw signal with no language model helping out; the best individual participant hit 22%. A fine-tuned language model does the heavy lifting at the sentence level, turning noisy, error-prone character guesses into something coherent.

Until now, reliable brain-to-text meant an actual implant. We watched Casey Harrell, who lost his ability to speak to ALS, get his voice back through exactly that kind of surgical device back in June. It used electrode arrays placed directly into his speech motor cortex, reading a few hundred neurons at a time. China's NEO implant, the first invasive brain-computer interface cleared for commercial sale anywhere, beat Neuralink to market the same month. Meta's version skips the operating room entirely. It's still a research result, not a product. Real-time use hasn't been demonstrated yet, and a 39% word error rate is still rough for daily use, but the gap between a scalpel and a magnetometer just got meaningfully smaller, for a technology built for people who've lost the ability to speak or move on their own.

The Decoder report Meta FAIR Brain2Qwerty v2 non-invasive brain-to-text AI using magnetoencephalography MEG word error rate 39 percent best participant 22 percent closing the gap with surgical brain implants no surgery required Qwen3 language model sentence reconstruction
the-decoder.com · July 2026
Why this matters: if you or someone you know lives with paralysis or a condition that affects speech, this is still research-stage, not a clinical device, but it's the more accessible track, no surgery, and a lower cost ceiling than an implant, worth watching as an alternative as it moves toward the clinic. Action this week: ask a care team or a university BCI research program about non-invasive trial eligibility as this technology develops. If you work in accessibility tech, healthcare, or assistive-device policy, note that the bottleneck right now is hardware, not the AI model — portable, room-temperature MEG scanners are the unlock Meta's own researchers name, so that's the thing to track for when this actually reaches patients.

the-decoder.com: Meta's non-invasive brain-to-text AI is closing the gap with surgical implants (July 2026)

» What to watch this week

Tomorrow's signal lands here.