Illustration of a hacker exploiting Meta's AI chatbot to hijack Instagram accounts by changing email addresses and bypassing security.
Illustration of a hacker exploiting Meta's AI chatbot to hijack Instagram accounts by changing email addresses and bypassing security.
Billede genereret af AI

Meta patches ai chatbot flaw used to hijack instagram accounts

Billede genereret af AI

Hackers exploited Meta's AI support chatbot to take over Instagram accounts by tricking it into changing associated email addresses. The vulnerability allowed password resets without two-factor authentication after matching locations via VPN. Meta resolved the issue with an emergency patch on May 29.

The exploit involved starting a password reset and prompting the chatbot to update the email on targeted accounts. Security researchers reported the method active since February and widely discussed on Telegram since March. High-profile accounts compromised included the Barack Obama White House account, which posted pro-Iranian images, and the Chief Master Sergeant of Space Force account, along with others like Sephora and short handles valued above $1 million on the gray market.

Hvad folk siger

Users reacted with skepticism about AI chatbots having write access to accounts without verification, concern over easy exploits via prompts and VPN, warnings that similar AI-related bugs will increase, and emphasis on enabling 2FA. Discussions highlighted the patch but noted risks of recurrence and lack of human support.

Relaterede artikler

Illustration depicting Meta employee under invasive AI surveillance monitoring at work, amid layoffs and staff backlash.
Billede genereret af AI

Meta tracks US employees' computer interactions for AI training amid staff backlash and layoffs

Rapporteret af AI Billede genereret af AI

Meta is deploying software on US employees' work computers to monitor keystrokes, clicks, mouse movements, and screenshots in work apps for AI training data. Internal memos reveal no opt-out option, sparking employee discomfort, as the company invests billions in AI while cutting thousands of jobs.

Meta disclosed that more than 20,000 Instagram accounts were stolen last week in a hacking operation that used an AI support bot.

Rapporteret af AI

Meta has begun testing a new AI chatbot on Threads that users are unable to block or opt out of, sparking widespread frustration across the platform. The public-facing account has drawn angry replies and become the top trend with over a million posts. Testing is currently limited to a handful of countries.

Ubuntu's official Twitter account posted a now-deleted tweet promoting a fake AI agent that directed users to a cryptocurrency scam. The incident follows a five-day DDoS attack on Canonical's web services that ended earlier this month.

Rapporteret af AI

A vulnerability in Google Gemini on Android allowed crafted notifications from apps like WhatsApp and Slack to manipulate the AI's responses and connected tools. The issue, discovered by SafeBreach, has been addressed through server-side changes.

Dette websted bruger cookies

Vi bruger cookies til analyse for at forbedre vores side. Læs vores privatlivspolitik for mere information.
Afvis