Instagram Account Hijacks Expose the Security Risks of AI-Powered Support
2026-06-02T20:51:51Z•fd9932a16f5df1751f5b97bf858960ef418acaf6ffac99cf65832dc84ec008c1
AI-support-abuseC2-via-SteamCIFSwitchCISACVE-2024-21182CVE-2026-0257CVE-2026-8732ENISA-NIS360GoDaddyInstagramLinux-privilege-escalationMetaOraclePAN-OSPalo-AltoWP-Maps-ProWebLogicWordPressaccount-hijackknown-exploited-vulnerabilitieslocation-datamalwareransomware-ops
What happened
Feed highlights multiple high-impact incidents: attackers abused Meta’s AI support chatbot to reset Instagram passwords and hijack accounts; CISA added known-exploited flaws including a Palo Alto PAN-OS vulnerability (CVE-2026-0257) — which Rapid7 observed being actively exploited — and an Oracle WebLogic-related CVE (CVE-2024-21182). A critical WordPress plugin bug (CVE-2026-8732) lets unauthenticated actors create admin accounts (thousands of attacks observed and the plugin has ~15k installs). GoDaddy researchers found ~1,980 WordPress sites infected with malware using Steam profile comments
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- fd9932a16f5df1751f5b97bf858960ef418acaf6ffac99cf65832dc84ec008c1
- Enrichment time
- 2026-06-02T20:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.