Hackers have been hijacking Instagram accounts at scale by exploiting Meta's AI support chatbot. And, as if that weren't bad enough, the technique required no technical skill whatsoever. Read more in my article on the Fortra blog.

Cybercriminals are reportedly exploiting a vulnerability in Meta's AI-powered support chatbot to gain unauthorized access to Instagram accounts. The method, which requires no specialized technical expertise, allows attackers to hijack accounts rapidly and at scale.
The exploitation hinges on the interaction between users and Meta's AI chatbot, which is designed to assist with account recovery and support issues. While the specifics of the exploit are not detailed, the process appears to leverage the chatbot's functionalities to bypass standard security measures.
This attack vector bypasses the need for traditional hacking techniques such as brute-force attacks or phishing. Instead, attackers are able to manipulate the chatbot's responses or exploit its decision-making process to gain control of user accounts.
The ease with which accounts can be compromised raises significant concerns about the security of Meta's support infrastructure and the potential for widespread account takeovers. The ability for attackers to operate "at scale" suggests a systematic approach to exploiting this vulnerability.
Instagram users are advised to remain vigilant regarding their account security. While specific mitigation steps for this particular exploit are not yet publicly available, general best practices for account security remain crucial.
This includes enabling two-factor authentication on all accounts, using strong and unique passwords, and being cautious of any unsolicited communications or requests for personal information. Users should also regularly review their account activity for any suspicious behavior.
The incident highlights the growing risks associated with AI-powered support systems and the need for robust security protocols to prevent their misuse. As AI becomes more integrated into online services, ensuring the security of these systems is paramount.
Meta has not yet issued a public statement regarding this specific exploitation of its AI chatbot. Further details on the vulnerability and potential countermeasures are anticipated as the situation develops.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets