Vulnerabilità · 113 giorni fa
L’assunzione errata è che l’account recovery sia più sicura del login. Qui, il canale di reset stesso forniva accesso quando l’email di destinazione non era collegata all’account, quindi cambiare la password poteva diventare il modo di entrare dell’attacker se la 2FA era disattivata.
4 fonti che coprono questa storia
Hackers used Meta's AI support system to hijack over 20,000 Instagram accounts - Help Net Security
Meta revealed that a flaw in Instagram's AI-assisted account recovery system led to 20,225 account takeovers.
Meta AI Bug Exposes Over 20,000 Instagram Accounts
Meta confirms an AI tool vulnerability led to unauthorized access to Instagram accounts after a failure in email verification during password reset
Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse
The social media giant has informed authorities about the impact of the recent attack involving an account recovery support tool.
Over 20,000 Instagram accounts stolen in Meta AI support hack
Meta has revealed that 20,225 Instagram users had their accounts hijacked in a recent incident where attackers used Meta's AI-powered support system to reset passwords.
Part of the PlainSec briefing for 2026-06-08