Monday , September 14 2026

Hackers Use Meta’s AI Bot to Take Over Instagram Accounts

Many Instagram users lost access to their accounts because attackers tricked Meta’s AI support tools into thinking they were the real owners. Many users can’t get back in because the platform only uses AI or chatbots for help, without any human support.

On Monday, many people with valuable accounts said they suddenly couldn’t get into their accounts. They claimed their identities were checked using facial scans and they had set up safety measures like two-factor authentication (2FA).

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

An unknown security expert called Nightmare Eclipse has drops a new Microsoft Defender flaw called "ShieldCrash" right after Microsoft released...
Read More
Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take...
Read More
cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

Among the impacted accounts were one previously used by the Obama White House team, one belonging to app researcher Jane Manchun Wong, @hey, and @korn.

The owner of the @korn account, who noted that the band never officially claimed the account and is using another one, expressed frustration with Meta’s recovery mechanism, which had put them in a time-wasting loop.

“I spent 6 hours trying to get human support, and Meta’s support AI gave me 4 broken links in a row,” explained the user identifying as Kornel.

“We’re at the point where one AI stole it, and another can’t fix it, zero humans in the loop anywhere,” the @korn account owner said.

Some reporters say the account-hijacking attacks were not serious. The attackers chatted with Meta’s AI assistant, made it believe they were the real account owner, and fooled it into changing the email linked to the account.

The takeover begins when the hacker uses the “forgot password” option because the account is hacked. When Instagram’s AI asks the user for a selfie to verify, the hacker takes a photo from the person’s account, changes it into a video with AI, and sends it to Meta for proof.

User André says that “Meta’s AI just accepts it because it can’t tell the difference between a real selfie and an AI-generated video of someone’s face.” They also added that the takeover method bypasses 2FA protections.

“Then you try to recover your account, and you’re talking to a chatbot that has zero ability to help. You can’t escalate to a human. You’re just stuck. Your asset is gone, and there’s no one to call,” André said.

Mitigation for Users:

Meta says the certain problem is fixed, but stealing accounts is still a risk. Important steps to strengthen the account:

Switch from SMS-based 2FA to an authenticator app (Google Authenticator, Authy) or a hardware security key to eliminate SIM-swap exposure.
Use a private, unlisted email not publicly associated with your name, website, or LinkedIn profile.
Generate fresh backup recovery codes under Security Settings and store them offline in a password manager or in a physical format not in email drafts.
Audit active sessions via Settings & Privacy → Accounts Center → Password and Security → Where You’re Logged In, and terminate any unrecognized sessions.
Never click links in unexpected password reset emails from Instagram; navigate directly to the app to verify your linked contact information.

Check Also

ShinyHunters

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center …