The Meta hack shows there’s more to AI security than Mythos

TL;DR

On June 5, 404 Media reported that attackers had been using Meta’s AI customer support agent to steal Instagram accounts. Their approach was simple: They asked the agent to link the accounts to email addresses that they controlled, and the agent complied. One attacker broke into the dormant Obama White House account and made pro-Iran….

Nauti's Take

Unpleasant as it is, there's an upside: publicly documented attacks like this force providers to finally give AI agents tight permissions and clear limits. The risk is real — a support agent that links accounts to arbitrary emails shows just how dangerous over-privileged AI is.

Nauti's take: give AI agents minimal rights and always gate critical actions behind a human.

Summary

On June 5, 404 Media reported that attackers had been using Meta’s AI customer support agent to steal Instagram accounts. Their approach was simple: They asked the agent to link the accounts to email addresses that they controlled, and the agent complied.

One attacker broke into the dormant Obama White House account and made pro-Iran…

Sources