steal Meta accounts via the AI support agent
2026-06-01 20:10:17.600296+02 by Dan Lyke 0 comments
Give tools to your AI support bots. What could go wrong? 404 Media: Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked. (Among other places, via Tara Calishain).
Related, and I missed the source, but I saw a reference to one of the code assistant chatbots writing to root-owned files by using the fact that they were in the "docker" group, and that they could create external mounts to docker containers, and then running the process overwriting the files as root inside the container.
I didn't track down the full source, and I don't pretend to understand Docker configs, but it sure seems like giving these things access to tools is fraught...