<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Chatbot on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/chatbot/</link><description>Recent content in Chatbot on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 04 Jun 2026 11:04:09 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/chatbot/index.xml" rel="self" type="application/rss+xml"/><item><title>Meta AI Chatbot Exploited to Hijack Instagram Accounts</title><link>https://zxcloudsecurity.co.uk/posts/meta-ai-chatbot-instagram-account-takeover/</link><pubDate>Thu, 04 Jun 2026 11:04:09 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/meta-ai-chatbot-instagram-account-takeover/</guid><description>Hackers are abusing Meta&amp;#39;s AI support chatbot to take over Instagram accounts via social engineering. Learn what this means for AI trust boundaries.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://www.schneier.com/blog/archives/2026/06/hacking-metas-ai-chatbot.html">Schneier on Security</a></p>
<hr>
<p>Attackers are exploiting Meta&rsquo;s AI support chatbot to hijack Instagram accounts by social-engineering the bot into adding a hacker-controlled email address and triggering a password reset. The attack requires no technical vulnerability in the traditional sense — the AI simply complies with the request after a verification code exchange. This highlights a significant trust and authorisation flaw in how Meta&rsquo;s AI assistant handles account management actions on behalf of unauthenticated parties.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Treat AI-powered support agents as a privileged access vector and apply the same controls you would to any account recovery flow — ensure they cannot perform account modifications without verified, out-of-band identity confirmation tied to the existing account owner, not the requester.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.schneier.com/blog/archives/2026/06/hacking-metas-ai-chatbot.html">Hacking Meta’s AI Chatbot</a></p>
]]></content:encoded></item></channel></rss>