Sometimes it's "What happens when attackers learn how to manipulate the AI itself?"
Instagram has patched a vulnerability that reportedly allowed threat actors to hijack accounts by exploiting Meta's AI-powered Support Assistant. According to reports, attackers could use a VPN to appear closer to a target's location, interact with the chatbot, add a new email address to the victim's account, and ultimately gain access to password reset functionality.
What's particularly concerning is that the attack allegedly didn't require compromising the victim's actual email account. Instead, the exploit focused on abusing trust in an automated support workflow.
https://www.technadu.com/instagram-patches-meta-ai-support-assistant-hijacking-vulnerability/628836/
Do you think organizations are moving too quickly to automate sensitive support functions, or is this simply part of the learning curve for AI-powered services?
#Cybersecurity #AI #AccountSecurity #InfoSec #SocialEngineering






