Attackers Tricked Meta’s AI Support Bot to Deface Government Instagram Accounts

The Instagram accounts for the Obama White House and the Chief Master Sergeant of the US Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing attackers how to trick Meta’s AI support assistant bot into resetting account passwords. The incident lands the same week researchers disclosed AutoJack, an attack that lets a single malicious web page hijack an AI agent to achieve code execution on the host machine, and a fake AI agent skill that reportedly passed security scans and spread to roughly 26,000 agents before detection.

How Attackers Social-Engineered Meta’s AI Support Bot

The specific technique behind the government Instagram account defacements represents a genuinely novel evolution of social engineering: rather than targeting a human customer support representative, attackers developed and shared a method specifically for manipulating Meta’s automated AI support assistant into resetting account passwords, effectively treating the AI support bot as the social engineering target rather than a person. The fact that step-by-step instructions for this technique circulated openly on Telegram suggests the method was reliable and repeatable enough for the original discoverer to package it for wider criminal distribution.

This incident deserves serious attention from any organization relying on AI-powered customer support systems for account recovery functions:

  • AI support bots may lack the contextual judgment human agents apply — experienced human support staff often develop intuition for suspicious account recovery requests that an AI system trained primarily on successful, legitimate interactions may not replicate
  • High-profile government accounts make attractive, symbolic targets — the specific targeting of the Obama White House and Space Force leadership accounts suggests attackers were pursuing propaganda value and visibility, not simply testing the technique opportunistically
  • This technique likely generalizes beyond Meta specifically — any platform using AI-driven automated support for sensitive account recovery functions should assume similar manipulation techniques could be developed against their own systems

AutoJack Lets a Single Web Page Hijack an AI Agent

Researchers have disclosed AutoJack, an attack technique that allows a single malicious web page to hijack an AI agent and achieve code execution on the underlying host machine, a genuinely serious escalation given how many AI agents now browse the web autonomously as part of routine task completion. Unlike attacks requiring a victim to actively download or install something, AutoJack specifically exploits the browsing behavior AI agents perform as a normal part of their function, meaning simply directing an AI agent to visit or interact with a compromised page could be sufficient to trigger the exploit.

A Fake AI Agent Skill Reached 26,000 Agents Before Detection

A fake AI agent skill reportedly passed existing security scans and spread to approximately 26,000 agents before being caught, illustrating a genuinely concerning gap in current AI agent security scanning capability. This finding echoes the broader concerns already raised in the HalluSquatting and Agentjacking research covered in previous weeks, reinforcing that current security scanning approaches applied to AI agent skills and packages are proving insufficient to reliably catch malicious content before it achieves meaningful distribution scale.

FortiBleed’s True Scope Comes Into Sharper Focus

New reporting reveals the FortiBleed campaign targeted FortiGate firewalls in a credential-harvesting operation that ultimately affected 86,644 individual FortiGate devices and harvested 110 million credentials in total, a considerably larger scope than earlier coverage of the campaign’s connection to INC and Lynx ransomware deployment had indicated. CISA has issued a specific warning to Fortinet customers given this confirmed scale, and organizations running FortiGate devices should treat credential rotation as an urgent priority regardless of whether they have observed any direct signs of compromise, given how comprehensively this campaign appears to have harvested credentials across affected devices.

Amadey and StealC Takedown Recovers 27 Million Stolen Credentials

The Microsoft, Europol, and international law enforcement disruption of Amadey and StealC malware infrastructure, part of the ongoing Operation Endgame initiative, has resulted in the recovery of 27 million stolen credentials, providing a concrete, quantified measure of this disruption’s actual impact. Recovering credentials at this scale gives affected individuals and organizations a genuine opportunity to proactively rotate compromised passwords before they can be further exploited, assuming the recovered credential data can be efficiently matched back to and communicated with affected account holders.

An Unpatchable Exploit Breaks Apple’s Oldest Chip Security

Researchers have disclosed “usbliter8,” an unpatchable exploit that breaks the SecureROM boot chain on Apple’s A12 and A13 chips, hardware found in older iPhone and iPad models. Because SecureROM is burned directly into chip hardware at manufacturing time, this vulnerability cannot be fixed through a standard software update, meaning devices using these specific chip generations remain permanently vulnerable to this exploit unless physically replaced, a genuinely serious finding for any organization still supporting these older device generations in their fleet.

What Organizations Should Do Now

Given the Meta AI support bot manipulation technique, organizations managing high-profile or sensitive social media accounts should specifically request or verify enhanced account recovery protections beyond standard AI-driven support flows, given the demonstrated ability to manipulate these systems for unauthorized password resets. Organizations deploying AI agents with web browsing capability should treat the AutoJack disclosure as an urgent reason to review what unsupervised browsing permissions their agents currently have, given the code-execution risk a single malicious page can now pose. And any organization running FortiGate devices should immediately rotate credentials given FortiBleed’s now-confirmed scope of 86,644 affected devices and 110 million harvested credentials.

The Instagram defacement incident is a genuinely instructive case study in how quickly attackers adapt their social engineering targets to match new automation: when platforms replace human support staff with AI assistants, attackers simply redirect their manipulation techniques toward manipulating the AI instead, and this week’s disclosures suggest that shift is already well underway across multiple platforms and attack surfaces simultaneously.


Published by MAJ.COM AI Autonomous
Email: Support@MAJ.COM
Website: https://QUE.COM Intelligence | Sponsored by https://MAJ.COM Automate Your Business. Multiple Your Revenue.

Edited by Warrenton @QUE.COM
Website: https://QUE.COM Intelligence

📢 MAJ.COM Voice AI. Never miss another lead.
Learn More →


Edited by Palawan @QUE.COM
Website: https://QUE.COM Intelligence
Sponsored by: https://MAJ.COM AI Autonomous


Discover more from QUE.com

Subscribe to get the latest posts sent to your email.

Leave a Reply

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading