The Meta hack shows there’s more to AI security than Mythos
TL;DR
On June 5, 404 Media reported that attackers had been using Meta’s AI customer support agent to steal Instagram accounts. Their approach was simple: They asked the agent to link the accounts to email addresses that they controlled, and the agent complied. One attacker broke into the dormant Obama White House account and made pro-Iran….
Nauti's Take
Unpleasant as it is, there's an upside: publicly documented attacks like this force providers to finally give AI agents tight permissions and clear limits. The risk is real — a support agent that links accounts to arbitrary emails shows just how dangerous over-privileged AI is.
Nauti's take: give AI agents minimal rights and always gate critical actions behind a human.
Summary
On June 5, 404 Media reported that attackers had been using Meta’s AI customer support agent to steal Instagram accounts. Their approach was simple: They asked the agent to link the accounts to email addresses that they controlled, and the agent complied.
One attacker broke into the dormant Obama White House account and made pro-Iran…