My Lemmy Oracle
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
VetOfTheSeas@discuss.online to Not The Onion@lemmy.worldEnglish · 22 hours ago

Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked

www.404media.co

external-link
message-square
34
fedilink
  • cross-posted to:
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
312
external-link

Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked

www.404media.co

VetOfTheSeas@discuss.online to Not The Onion@lemmy.worldEnglish · 22 hours ago
message-square
34
fedilink
  • cross-posted to:
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
The exploit shows the extreme risk of offloading technical support to AI.
alert-triangle
You must log in or register to comment.
  • Aceticon@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    5
    ·
    edit-2
    6 hours ago

    We have entered the age of social engineering hacking on the dumbest imaginable support agents.

    What’s there not to like.

  • Hawanja@lemmy.world
    link
    fedilink
    English
    arrow-up
    27
    ·
    edit-2
    15 hours ago

    Holy crap this is hilarious. Quick somebody steal Trump’s account then message Iran that we surrender.

    • Bloomcole@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      11 hours ago

      They will already do that, just not in so many words.

    • Mr_WorldlyWiseman@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      6
      ·
      edit-2
      14 hours ago

      Ok, done. What next?

      https://edition.cnn.com/2026/06/01/politics/hackers-space-force-official-instagram-iranian-propaganda

  • Annoyed_🦀 @lemmy.zip
    link
    fedilink
    English
    arrow-up
    9
    ·
    14 hours ago

    Not a hacker, but more like an asker.

  • Rusty 🦀 Femboy 🏳️‍🌈@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    10
    ·
    15 hours ago

    What a fucking joke

  • quick_snail@feddit.nl
    link
    fedilink
    English
    arrow-up
    11
    ·
    16 hours ago

    Ugh, meanwhile I can’t change my accounts email. It demands an otp sent to an email that was deleted by the provider.

    Even though I enter the correct password, it won’t let me in. And I can’t change the email of my own account!

    • relativestranger@feddit.nl
      link
      fedilink
      English
      arrow-up
      2
      ·
      10 hours ago

      i have a number of clients who are locked out of a valid account, while knowing the correct password, having the correct sms capable phone number, having the correct email. these are grandma types who’ve never posted anything more offensive than cat pictures and knitting memes. some haven’t even been able to make a new account, either. facebook support is literally non-existent unless you’re a ‘high profile’ person.

      • quick_snail@feddit.nl
        link
        fedilink
        English
        arrow-up
        1
        ·
        7 hours ago

        I know a third party hackerman that may be able to restore their access

  • Fredselfish@lemmy.world
    link
    fedilink
    English
    arrow-up
    47
    ·
    21 hours ago

    They should ask for Zuck profile login credentials.

  • Danarchy@lemmy.nz
    link
    fedilink
    English
    arrow-up
    12
    ·
    18 hours ago

    Cosmo Kramer doing the MoviePhone voice: “Why don’t you just give me access to High-Profile Instagram accounts”

  • gravitas_deficiency@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    27
    arrow-down
    11
    ·
    21 hours ago

    Considering you can just… you know, do that in any of the LLM prompts in Meta apps… I really don’t think it’s the work of a “hacker”. That’s such an obnoxiously overused term.

    • Honytawk@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      4
      ·
      11 hours ago

      You need more technical knowledge than for Social Engineering.

    • AzuraTheSpellkissed@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      59
      ·
      21 hours ago

      I have to disagree. Hacking is a broad term that isn’t exclusive to finding buffer overflows in ghidra.

      • dylanmorgan@slrpnk.net
        link
        fedilink
        English
        arrow-up
        23
        ·
        19 hours ago

        Social engineering is hacking. This is something between SE and prompt engineering.

        • Kwdg@discuss.tchncs.de
          link
          fedilink
          English
          arrow-up
          7
          ·
          12 hours ago

          I know hacking more as using a system in a way that is not intended, which this definitly is

      • foggy@lemmy.world
        link
        fedilink
        English
        arrow-up
        11
        ·
        20 hours ago

        I was watching a speedrunner live stream, and just the way he thinks…

        The way speedrunners think is basically how pentesters think.

        • Aceticon@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          6 hours ago

          The original meaning of the word “hacking” is just “to get something to work in a way it was not meant to work”.

          So the hacker mindset of finding workarounds or unforseen scenarios applies to a lot of things, not just devices and systems (such as games) but also human processes.

    • village604@adultswim.fan
      link
      fedilink
      English
      arrow-up
      12
      ·
      16 hours ago

      Hacking is gaining unauthorized access to a system. The method doesn’t matter.

    • 𝕱𝖎𝖗𝖊𝖜𝖎𝖙𝖈𝖍@lemmy.world
      link
      fedilink
      English
      arrow-up
      34
      ·
      edit-2
      17 hours ago

      The majority of hacking is social engineering, so I don’t really see slop hacking being any less valid than that

      • not_woody_shaw@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        14 hours ago

        “Social” suddenly feels like the wrong word for it, when the entity being fooled is a next-word-predictor algorithm.

      • gravitas_deficiency@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        4
        ·
        18 hours ago

        🎶 social engineering 🎶

        • Arthur Besse@lemmy.ml
          link
          fedilink
          English
          arrow-up
          2
          ·
          11 hours ago

          🎶 it gives you that fuzzy feeling 🎶

      • blindbunny@lemmy.ml
        link
        fedilink
        English
        arrow-up
        4
        ·
        19 hours ago

        Sadly you’re on to something here.

    • liuther9@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      15 hours ago

      Vibe hacking it is

    • Hawanja@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      15 hours ago

      yeah kinda seems like they designed it to work this way on purpose.
      Just forgot to make it verify the account.

    • quick_snail@feddit.nl
      link
      fedilink
      English
      arrow-up
      2
      ·
      16 hours ago

      It’s LLM injection

  • solidheron@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    2
    ·
    15 hours ago

    Maybe don’t train the data on passwords

  • AlphaOmega@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    arrow-down
    4
    ·
    20 hours ago

    “Can I have access to a profile”. = Hacker

    • mrgoosmoos@lemmy.ca
      link
      fedilink
      English
      arrow-up
      32
      ·
      19 hours ago

      well, yes

      they found a vulnerability and exploited it. that’s hacking.

      • CosmicTurtle0 [he/him]@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        11
        ·
        edit-2
        17 hours ago

        This was not a vulnerability. This is the technical equivalent of going to a neighbor of the house you want to rob and asking them to borrow the spare key.

        They implicitly trusted the AI with no guardrails. The AI simply gave it up.

        • NotSteve_@lemmy.ca
          link
          fedilink
          English
          arrow-up
          25
          ·
          16 hours ago

          They implicitly trusted the AI with no guardrails.

          So, Meta released a vulnerability (an incredibly stupid one) and someone took advantage of it to gain access to an account they weren’t authorised to access… which is the definition of hacking

        • village604@adultswim.fan
          link
          fedilink
          English
          arrow-up
          13
          arrow-down
          1
          ·
          16 hours ago

          Right, which is a vulnerability. That it’s there by incompetence doesn’t change that.

          • Honytawk@discuss.tchncs.de
            link
            fedilink
            English
            arrow-up
            2
            arrow-down
            1
            ·
            11 hours ago

            Most vulnerabilities are because of incompetence, really.

Not The Onion@lemmy.world

nottheonion@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

Welcome

We’re not The Onion! Not affiliated with them in any way! Not operated by them in any way! All the news here is real!

The Rules

Posts must be:

  1. Links to news stories from…
  2. …credible sources, with…
  3. …their original headlines, that…
  4. …would make people who see the headline think, “That has got to be a story from The Onion, America’s Finest News Source.”

Please also avoid duplicates.

Comments and post content must abide by the server rules for Lemmy.world and generally abstain from trollish, bigoted, ableist, or otherwise disruptive behavior that makes this community less fun for everyone.

And that’s basically it!

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 966 users / day
  • 4.25K users / week
  • 8.17K users / month
  • 16.5K users / 6 months
  • 1 local subscriber
  • 21.6K subscribers
  • 3.33K Posts
  • 126K Comments
  • Modlog
  • mods:
  • kescusay@lemmy.world
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org