< Back to all clusters
[TECHNOLOGY] · United States, Australia, Thailand, Israel · 2 sources

Meta AI support tool bug exposes over 20,000 Instagram accounts

Meta confirmed that a flaw in its High Touch Support (HTS) AI tool allowed threat actors to obtain password‑reset links for more than 20,000 Instagram accounts in late May. The tool failed to verify that the email address supplied matched the account’s registered email, sending reset links to unassociated addresses. Attackers could then reset passwords and access accounts that lacked two‑factor authentication. Meta has disabled the tool while a fix is implemented.

In a separate legal move, Meta asked a U.S. federal judge to hold Israeli spyware vendor NSO Group in contempt for allegedly continuing WhatsApp‑targeted phishing campaigns despite a permanent injunction. Meta said it disrupted NSO‑linked social‑engineering attempts and removed test accounts and groups on WhatsApp.

The broader cyber‑security roundup for early June highlighted additional threats: Australian and Thai police uncovered a Cambodian scam script impersonating AFP officers; a Magecart campaign abused Google Tag Manager and Stripe APIs to skim payment data; the Miasma supply‑chain worm infected Red Hat npm packages; and a critical zero‑day in Gogs was patched. These incidents illustrate the diverse and evolving nature of cybercrime worldwide.

Sources

NEWS ROUNDUP – 8th June 2026 [digitalforensicsmagazine.com]
about 2 months ago