Instagram Account Hijacks Expose the Security Risks of AI-Powered Support

2026-06-03T02:51:48Z79befbbc10bfbeefb0e6a6603bfe509932a6fb73267301cbcd3064a93d0a2476
account-takeoverai-abuseenisaglobalprotectknown-exploited-vulnerabilitylinux-cvelocation-privacymalware-c2palo-altoprivilege-escalationransomware-activitysteam-c2web-exploitationwordpresswp-maps-pro

What happened

Multiple active and high-impact security issues reported: attackers abused Meta’s AI support chatbot to reset Instagram passwords and hijack accounts; Rapid7 observed active exploitation of Palo Alto PAN-OS cookie-forgery (CVE-2026-0257) against multiple customers and CISA added related flaws to its KEV list; WP Maps Pro has an unauthenticated admin-creation flaw (CVE-2026-8732) with thousands of attack attempts; GoDaddy discovered ~1,980 WordPress sites infected with malware that uses Steam profile comments as C2; a 19‑year‑old Linux logic bug (CIFSwitch) enables local root on several distros

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
79befbbc10bfbeefb0e6a6603bfe509932a6fb73267301cbcd3064a93d0a2476
Enrichment time
2026-06-03T02:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Instagram Account Hijacks Expose the Security Risks of AI-Powered Support · Baitaphish