
Summaries like this, in your inbox every morning.
Sign up free →On June 5, 404 Media reported that attackers used Meta's AI customer support agent to steal Instagram accounts by asking the agent to link accounts to email addresses they controlled. One attacker broke into the dormant Obama White House account and made pro-Iran posts; others took over accounts with valuable, single-word handles, possibly to sell them.
The hack exploited a fundamental weakness in AI agents (AI systems that take autonomous actions to complete tasks): unlike humans, they can be tricked into performing sensitive operations without proper verification, such as changing account email addresses without security questions. The attackers only needed a VPN matching the true account owner's location before directly requesting the email change.
Experts say the vulnerability should have been caught before deployment through red-teaming (a security practice where developers try to attack a system to discover flaws before release). Neil Gong, a Duke University professor, called it surprising that such a simple problem slipped through at a company with Meta's AI and cybersecurity expertise.
No discussion yet for this article
Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.
Get Started FreeFree · takes 30 seconds · unsubscribe anytime
5 minutes a day. The AI essentials.
200+ sources · Email / LINE / Slack