Instagram Account Hijacks Expose the Security Risks of AI-Powered Support
2026-06-03T02:51:48Z•79befbbc10bfbeefb0e6a6603bfe509932a6fb73267301cbcd3064a93d0a2476
account-takeoverai-abuseenisaglobalprotectknown-exploited-vulnerabilitylinux-cvelocation-privacymalware-c2palo-altoprivilege-escalationransomware-activitysteam-c2web-exploitationwordpresswp-maps-pro
What happened
Multiple active and high-impact security issues reported: attackers abused Meta’s AI support chatbot to reset Instagram passwords and hijack accounts; Rapid7 observed active exploitation of Palo Alto PAN-OS cookie-forgery (CVE-2026-0257) against multiple customers and CISA added related flaws to its KEV list; WP Maps Pro has an unauthenticated admin-creation flaw (CVE-2026-8732) with thousands of attack attempts; GoDaddy discovered ~1,980 WordPress sites infected with malware that uses Steam profile comments as C2; a 19‑year‑old Linux logic bug (CIFSwitch) enables local root on several distros
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 79befbbc10bfbeefb0e6a6603bfe509932a6fb73267301cbcd3064a93d0a2476
- Enrichment time
- 2026-06-03T02:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.