Hackers used Meta’s AI support system to hijack over 20,000 Instagram accounts

2026-06-08T14:51:48Z5df62d9afaf8d9b6aa7d39c380fe675576b3bfbe7a237682f4d758e344e12950
AI-assisted account recoveryActive DirectoryCISACVE-2026-28318CVE-2026-50751Check PointConnectSecure Patch 360HTSHigh Touch SupportInstagramMetaOpenAI Lockdown Mode','ChatGPT'QilinRidge SecurityRidgeBotSamsung One UISolarWindsaccount takeoveractive exploitationlockdown modepatch managementpatchingransomwarevulnerability managementzero-day

What happened

Multiple security developments: Meta disclosed a flaw in its AI-assisted High Touch Support (HTS) account recovery that allowed attackers to reset passwords and hijack 20,225 Instagram accounts. A Qilin ransomware affiliate is exploiting a Check Point Remote/Mobile Access VPN authentication-bypass zero-day (CVE-2026-50751). CISA warned that SolarWinds Serv-U suffers an actively exploited DoS vulnerability (CVE-2026-28318) and ordered mitigations/patching for federal agencies. Other notable items include RidgeBot 7.0 (automated Active Directory attack simulation), ConnectSecure Patch 360 (MSP-­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
5df62d9afaf8d9b6aa7d39c380fe675576b3bfbe7a237682f4d758e344e12950
Enrichment time
2026-06-08T14:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.