LIVE · cybersecurity feed
Live wire
ai

Meta’s own AI chatbot to blame for Instagram accounts being stolen in seconds

Hackers have been hijacking Instagram accounts at scale by exploiting Meta's AI support chatbot. And, as if that weren't bad enough, the technique required no technical skill whatsoever. Read more in my article on the Fortra blog.

zeroday.news · 58d ago

Cybercriminals are reportedly exploiting a vulnerability in Meta's AI-powered support chatbot to gain unauthorized access to Instagram accounts. The method, which requires no specialized technical expertise, allows attackers to hijack accounts rapidly and at scale.

The exploitation hinges on the interaction between users and Meta's AI chatbot, which is designed to assist with account recovery and support issues. While the specifics of the exploit are not detailed, the process appears to leverage the chatbot's functionalities to bypass standard security measures.

This attack vector bypasses the need for traditional hacking techniques such as brute-force attacks or phishing. Instead, attackers are able to manipulate the chatbot's responses or exploit its decision-making process to gain control of user accounts.

The ease with which accounts can be compromised raises significant concerns about the security of Meta's support infrastructure and the potential for widespread account takeovers. The ability for attackers to operate "at scale" suggests a systematic approach to exploiting this vulnerability.

Instagram users are advised to remain vigilant regarding their account security. While specific mitigation steps for this particular exploit are not yet publicly available, general best practices for account security remain crucial.

This includes enabling two-factor authentication on all accounts, using strong and unique passwords, and being cautious of any unsolicited communications or requests for personal information. Users should also regularly review their account activity for any suspicious behavior.

The incident highlights the growing risks associated with AI-powered support systems and the need for robust security protocols to prevent their misuse. As AI becomes more integrated into online services, ensuring the security of these systems is paramount.

Meta has not yet issued a public statement regarding this specific exploitation of its AI chatbot. Further details on the vulnerability and potential countermeasures are anticipated as the situation develops.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.

vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.