RBlind
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
VetOfTheSeas@discuss.online to Not The Onion@lemmy.worldEnglish · 2 days ago

Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked

www.404media.co

external-link
message-square
34
link
fedilink
  • cross-posted to:
  • pcmasterrace@lemmy.world
  • technology@lemmy.world
  • cybersecurity@infosec.pub
  • cybersecurity@infosec.pub
323
external-link

Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked

www.404media.co

VetOfTheSeas@discuss.online to Not The Onion@lemmy.worldEnglish · 2 days ago
message-square
34
link
fedilink
  • cross-posted to:
  • pcmasterrace@lemmy.world
  • technology@lemmy.world
  • cybersecurity@infosec.pub
  • cybersecurity@infosec.pub
The exploit shows the extreme risk of offloading technical support to AI.
alert-triangle
You must log in or # to comment.
  • Hawanja@lemmy.world
    link
    fedilink
    English
    arrow-up
    30
    ·
    2 days ago

    Holy crap this is hilarious. Quick somebody steal Trump’s account then message Iran that we surrender.

    • Bloomcole@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      ·
      1 day ago

      They will already do that, just not in so many words.

    • Mr_WorldlyWiseman@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      7
      ·
      2 days ago

      Ok, done. What next?

      https://edition.cnn.com/2026/06/01/politics/hackers-space-force-official-instagram-iranian-propaganda

  • Aceticon@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    5
    ·
    1 day ago

    We have entered the age of social engineering hacking on the dumbest imaginable support agents.

    What’s there not to like.

  • Fredselfish@lemmy.world
    link
    fedilink
    English
    arrow-up
    48
    ·
    2 days ago

    They should ask for Zuck profile login credentials.

  • Annoyed_🦀 @lemmy.zip
    link
    fedilink
    English
    arrow-up
    9
    ·
    1 day ago

    Not a hacker, but more like an asker.

  • Rusty 🦀 Femboy 🏳️‍🌈@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    10
    ·
    2 days ago

    What a fucking joke

  • quick_snail@feddit.nl
    link
    fedilink
    English
    arrow-up
    11
    ·
    2 days ago

    Ugh, meanwhile I can’t change my accounts email. It demands an otp sent to an email that was deleted by the provider.

    Even though I enter the correct password, it won’t let me in. And I can’t change the email of my own account!

    • relativestranger@feddit.nl
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 day ago

      i have a number of clients who are locked out of a valid account, while knowing the correct password, having the correct sms capable phone number, having the correct email. these are grandma types who’ve never posted anything more offensive than cat pictures and knitting memes. some haven’t even been able to make a new account, either. facebook support is literally non-existent unless you’re a ‘high profile’ person.

      • quick_snail@feddit.nl
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 day ago

        I know a third party hackerman that may be able to restore their access

  • Danarchy@lemmy.nz
    link
    fedilink
    English
    arrow-up
    12
    ·
    2 days ago

    Cosmo Kramer doing the MoviePhone voice: “Why don’t you just give me access to High-Profile Instagram accounts”

  • gravitas_deficiency@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    27
    arrow-down
    11
    ·
    2 days ago

    Considering you can just… you know, do that in any of the LLM prompts in Meta apps… I really don’t think it’s the work of a “hacker”. That’s such an obnoxiously overused term.

    • AzuraTheSpellkissed@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      62
      ·
      2 days ago

      I have to disagree. Hacking is a broad term that isn’t exclusive to finding buffer overflows in ghidra.

      • dylanmorgan@slrpnk.net
        link
        fedilink
        English
        arrow-up
        23
        ·
        2 days ago

        Social engineering is hacking. This is something between SE and prompt engineering.

        • Kwdg@discuss.tchncs.de
          link
          fedilink
          English
          arrow-up
          7
          ·
          1 day ago

          I know hacking more as using a system in a way that is not intended, which this definitly is

      • foggy@lemmy.world
        link
        fedilink
        English
        arrow-up
        12
        ·
        2 days ago

        I was watching a speedrunner live stream, and just the way he thinks…

        The way speedrunners think is basically how pentesters think.

        • Aceticon@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          2
          ·
          1 day ago

          The original meaning of the word “hacking” is just “to get something to work in a way it was not meant to work”.

          So the hacker mindset of finding workarounds or unforseen scenarios applies to a lot of things, not just devices and systems (such as games) but also human processes.

    • 𝕱𝖎𝖗𝖊𝖜𝖎𝖙𝖈𝖍@lemmy.world
      link
      fedilink
      English
      arrow-up
      35
      ·
      edit-2
      2 days ago

      The majority of hacking is social engineering, so I don’t really see slop hacking being any less valid than that

      • not_woody_shaw@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        2 days ago

        “Social” suddenly feels like the wrong word for it, when the entity being fooled is a next-word-predictor algorithm.

      • gravitas_deficiency@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        4
        ·
        2 days ago

        🎶 social engineering 🎶

        • Arthur Besse@lemmy.ml
          link
          fedilink
          English
          arrow-up
          2
          ·
          1 day ago

          🎶 it gives you that fuzzy feeling 🎶

      • blindbunny@lemmy.ml
        link
        fedilink
        English
        arrow-up
        4
        ·
        2 days ago

        Sadly you’re on to something here.

    • village604@adultswim.fan
      link
      fedilink
      English
      arrow-up
      13
      ·
      2 days ago

      Hacking is gaining unauthorized access to a system. The method doesn’t matter.

    • Honytawk@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 day ago

      You need more technical knowledge than for Social Engineering.

    • liuther9@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 days ago

      Vibe hacking it is

    • Hawanja@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 days ago

      yeah kinda seems like they designed it to work this way on purpose.
      Just forgot to make it verify the account.

    • quick_snail@feddit.nl
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 days ago

      It’s LLM injection

  • AlphaOmega@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    arrow-down
    4
    ·
    2 days ago

    “Can I have access to a profile”. = Hacker

    • mrgoosmoos@lemmy.ca
      link
      fedilink
      English
      arrow-up
      32
      ·
      2 days ago

      well, yes

      they found a vulnerability and exploited it. that’s hacking.

      • CosmicTurtle0 [he/him]@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        11
        ·
        2 days ago

        This was not a vulnerability. This is the technical equivalent of going to a neighbor of the house you want to rob and asking them to borrow the spare key.

        They implicitly trusted the AI with no guardrails. The AI simply gave it up.

        • NotSteve_@lemmy.ca
          link
          fedilink
          English
          arrow-up
          25
          ·
          2 days ago

          They implicitly trusted the AI with no guardrails.

          So, Meta released a vulnerability (an incredibly stupid one) and someone took advantage of it to gain access to an account they weren’t authorised to access… which is the definition of hacking

        • village604@adultswim.fan
          link
          fedilink
          English
          arrow-up
          13
          arrow-down
          2
          ·
          2 days ago

          Right, which is a vulnerability. That it’s there by incompetence doesn’t change that.

          • Honytawk@discuss.tchncs.de
            link
            fedilink
            English
            arrow-up
            2
            arrow-down
            1
            ·
            1 day ago

            Most vulnerabilities are because of incompetence, really.

  • solidheron@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 days ago

    Maybe don’t train the data on passwords

Not The Onion@lemmy.world

nottheonion@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !nottheonion@lemmy.world

Welcome

We’re not The Onion! Not affiliated with them in any way! Not operated by them in any way! All the news here is real!

The Rules

Posts must be:

  1. Links to news stories from…
  2. …credible sources, with…
  3. …their original headlines, that…
  4. …would make people who see the headline think, “That has got to be a story from The Onion, America’s Finest News Source.”

Please also avoid duplicates.

Comments and post content must abide by the server rules for Lemmy.world and generally abstain from trollish, bigoted, ableist, or otherwise disruptive behavior that makes this community less fun for everyone.

And that’s basically it!

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 722 users / day
  • 4.17K users / week
  • 7.55K users / month
  • 16.5K users / 6 months
  • 2 local subscribers
  • 21.6K subscribers
  • 1.65K Posts
  • 62.8K Comments
  • Modlog
  • mods:
  • kescusay@lemmy.world
  • BE: 0.19.18
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org