Reading view

Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts

Meta’s AI support chatbot proved unusually helpful to hackers looking to steal and resell notable Instagram accounts—the hackers simply asking the bot to change the accounts’ associated email addresses while using VPN to mask their true locations.

Videos featuring the “shockingly easy” exploit have been circulating among Telegram groups for hackers and security researchers, according to 404 Media. The exploit allowed hackers to take over and flip valuable Instagram accounts worth hundreds of thousands of dollars on the gray market before Meta implemented an emergency patch on May 29. The Barack Obama White House account and the Chief Master Sergeant of Space Force’s account also posted pro-Iranian images and messages while they were temporarily compromised.

Attackers simply had to use a VPN to approximately match their location to the target Instagram account’s region, begin a password reset process, and then ask Meta’s AI support chatbot to change the email address associated with the account, according to 404 Media. It’s a very straightforward prompt injection attack.

Read full article

Comments

© Marcin Golba/NurPhoto via Getty Images

  •  

Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts

Meta’s AI support chatbot proved unusually helpful to hackers looking to steal and resell notable Instagram accounts—the hackers simply asking the bot to change the accounts’ associated email addresses while using VPN to mask their true locations.

Videos featuring the “shockingly easy” exploit have been circulating among Telegram groups for hackers and security researchers, according to 404 Media. The exploit allowed hackers to take over and flip valuable Instagram accounts worth hundreds of thousands of dollars on the gray market before Meta implemented an emergency patch on May 29. The Barack Obama White House account and the Chief Master Sergeant of Space Force’s account also posted pro-Iranian images and messages while they were temporarily compromised.

Attackers simply had to use a VPN to approximately match their location to the target Instagram account’s region, begin a password reset process, and then ask Meta’s AI support chatbot to change the email address associated with the account, according to 404 Media. It’s a very straightforward prompt injection attack.

Read full article

Comments

© Marcin Golba/NurPhoto via Getty Images

  •  

Meta’s own AI was exploited to hijack Instagram accounts

An image of Meta’s support AI

Meta's AI support chatbot helped hackers hijack Instagram accounts, as reported earlier by 404 Media. In a video shared on Telegram, a hacker shows how they could take over an account by asking Meta's chatbot to switch the email associated with someone else's profile and then reset the password.

The issue, which Meta says has since been patched, cropped up around the same time Barack Obama's White House account on Instagram was hacked. On Sunday, users noticed that the @obamawhitehouse account began posting images containing Iranian propaganda. Hackers appeared to have hijacked the Instagram accounts belonging to the US Space Force Chief Ma …

Read the full story at The Verge.

  •  

Meta tracking tool raises EU GDPR concerns

Meta Platforms reportedly acknowledged its controversial employee surveillance programme captures data from employees outside the US, raising fresh legal questions in Europe.

Reuters reported internal documentation it reviewed showed the company’s Model Capability Initiative (MCI) does capture data outside of the US.

MCI was introduced last month as a tool to record how US-based employees interact with their work computers by tracking mouse movements, clicks and navigation patterns across more than 200 apps and websites.

The goal of MCI is to use the employee-generated data to train AI agents capable of performing coding and white-collar tasks.

Meta told staff the programme is confined to US devices and stated safeguards are in place to protect sensitive information.

The news agency noted Meta acknowledged in a question-and-answer document provided to employees MCI will capture the contents of any emails or direct messages sent to US personnel, regardless of the sender’s ⁠location.

Meta spokesperson Dave Arnold told Reuters the company notified non-US employees the tool was running on the machines of US-based colleagues they might correspond with, describing the step as one of transparency.

A representative for Meta told Mobile World Live: “We’ve been clear that this tool is for US-based personnel only, and in the interest of transparency, we notified non-US employees that it was deployed on the computers of US colleagues they may email or chat with in the normal course of business.”

“We carefully considered and mitigated potential privacy risks in both the development and deployment of this tool, and we are committed to complying with applicable laws and regulations.” 

New regulatory exposure
Reuters stated the disclosure introduces new regulatory exposure in Europe, where technology companies are already fighting a series of heated legal battles over data collection.

Under the EU’s GDPR rules, the news site explained companies must establish a clear legal basis for processing personal data, disclose what is being collected and satisfy strict conditions around sensitive categories of information.

Kleanthi Sardeli, a legal expert at privacy advocacy group NOYB, told the news site even limited or incidental capture of EU employee data could put Meta in breach of GDPR rules.

A key question, she said, is whether data originally gathered for work communications can lawfully be repurposed to train an AI model.

The post Meta tracking tool raises EU GDPR concerns appeared first on Mobile World Live.

  •  

Meta legal action forces Facebook whistleblower to sit in silence at Hay festival

Sarah Wynn-Williams did not speak during event after lawyers warned of possible sanctions from tech firm

Facebook whistleblower Sarah Wynn-Williams was forced to sit in silence on stage at an event at Hay festival, after lawyers advised her not to speak because of ongoing legal action brought by Meta.

Wynn-Williams, whose bestselling memoir, Careless People, details her years working at Facebook, was due to appear in conversation with the investigative journalist Carole Cadwalladr and academic Tim Wu.

Continue reading...

© Photograph: Sam Hardwick

© Photograph: Sam Hardwick

© Photograph: Sam Hardwick

  •  
❌