Meta patches flaw that allowed MetaAI support bot to hand out password reset links without 2FA



  • Cybercriminals tricked Meta’s AI customer support agent into forwarding password reset codes
  • Stolen short‑handle accounts, valued at over $1M combined, were listed for sale across Telegram
  • Attack highlights risk of delegating sensitive tasks to AI systems

Cybercriminals successfully pulled off a social engineering attack against Meta’s customer support, tricking the representative into initiating a password reset sequence without asking for any identity verification.

The news here is that the representative was actually an AI agent, not a human being at all. The researchers who disclosed the attack stressed just how dangerous it is to hand over sensitive assignments to AI. Meta fixed it soon after.

https://cdn.mos.cms.futurecdn.net/Ct6gzt4QFsbxZWMKYcyU2Y-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img