frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Hackers Used Meta's AI Support Bot to Seize Instagram Accounts

https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/
48•panarky•1h ago

Comments

pseudosavant•1h ago
This simultaneously seems like: 1) such an obvious attack vector that it is extreme negligence to not have had planned for appropriate security protections against this, and 2) the most obvious outcome for Meta to be this security lax and stupid. If it doesn't hurt their ad sales, it doesn't matter to Meta.
jeffbee•1h ago
Instagram auth flow is still hosed as I write this. If I try to sign on via web to my account, which was "recovered" yesterday at least 8 times by me and by hackers, I get the most obnoxious recaptcha treatment I've ever seen with 4-6 different pages of "click the motorcycle" where all 16 squares contain motorcycles, and after I deal with that for several minutes it still just hangs on "we will now redirect you".
crooked-v•1h ago
"Hackers"? No. There's no hacking involved. It's literally just politely asking the bot to send you the login link.
TremendousJudge•1h ago
most "hacking" is just politely trying to login with user: root password: password
system2•58m ago
Social engineering is hacking.
jvanderbot•54m ago
Social engineering the engineered social interaction is _wild_.
Retr0id•47m ago
Most hacks can be expressed in terms of "literally just" something.
bell-cot•30m ago
I'd reserve "hack" for something requiring some technical skill. Or at least scripts or something written by someone with technical skill.

Kinda like how it ain't "breaking & entering" if you found the victim's diamond necklace in a plastic bin sitting at the curb.

dpoloncsak•46m ago
>It's literally just politely asking the bot to send you the login link.

Sounds like exploiting a system to access unauthorized data to me. I'd call it hacking.

metadat•1h ago
Already on the front page:

The newest Instagram “exploit” is the goofiest I've seen

https://news.ycombinator.com/item?id=48359102 - 180 comments

ajdude•32m ago
I know that HN requests that we don't editorialize the titles, but I feel like the article title for this thread better expresses what's happened at a glance than the "goofy exploit" article.
metadat•14m ago
When the title is too editorial HN staff will fix the title to be more accurate. But probably only if you email hn@ycombinator.com and ask for it! Without your help surfacing issues, there is too much volume day in and day out to keep up.
aspectop•1h ago
It might be Zuck who was just exploring his own platforms to see if they all can be destroyed like Metaverse or not
MacNCheese23•59m ago
old news https://news.ycombinator.com/item?id=48359102
341akhg•56m ago
Have you seen Meta or Instagram AI code? It is horrible. No one understands the whole PyTorch any more.

This is probably a vibe coded feature by someone who had to meet his minimum token quotas.

Or some genius who implemented a "sandbox" and thought that this time, this sandbox will work unlike all other sandboxes in history.

Instagram is of course even worse, since even the Python core developers there use all sorts of hacks. It is not clear if Python is involved in the login system though, but the culture is awful.

c3droid•54m ago
I'm still extremely surprised something has not overtaken Instagram in popularity and somehow Meta is still thriving. Shit is nuts.
Catloafdev•53m ago
Did the security engineers leave the building?
tcdent•31m ago
Everyone's gonna frame this as "AI is dumb".

And, yes, the current tech is pretty dumb.

But this is a blatant misapplication of the technology in an obviously sensitive use case with an implementation that's so exploitable the people driving it have certainly never heard the term "jailbreak" once in their lives.

Reminds me of a consulting call that I had with a very large internet provider about their new agentic chat support system.

"We're going to start with the request routing layer and move that to AI agents, and then work though the individual services."

I thought it was a wild architectural decision that they would choose to roll every single action that the system handled through an experimental layer. My advice was to start with a safe, repeatable process to validate the effectiveness in the wild, and then expand in the same manner, bringing edges in as they had "solved" the individual implementations.

So, while this is almost the exact opposite of that, choosing a high-value target with real repercussions as their leaf implementation still baffles me. Step zero of any AI integration plan should be prioritization. Companies are routinely failing at this very simple, not-even-technical aspect.

The newest Instagram “exploit” is the goofiest I've seen

https://www.0xsid.com/blog/meta-account-takeover-fiasco
826•ssiddharth•4h ago•205 comments

Florida sues OpenAI and Sam Altman over AI risks

https://www.politico.com/news/2026/06/01/openai-hit-with-florida-lawsuit-00944215
56•cyunker•4h ago•31 comments

AI Agent Guidelines for CS336 at Stanford

https://github.com/stanford-cs336/assignment1-basics/blob/main/CLAUDE.md
197•prakashqwerty•4h ago•91 comments

Should you normalize RGB values by 255 or 256?

https://30fps.net/pages/255-vs-256-division/
85•pplanu•3h ago•34 comments

Forget LASIK: Safer, cheaper vision correction without lasers or surgery

https://www.sciencedaily.com/releases/2026/05/260528074032.htm
27•bookmtn•1d ago•2 comments

CS336: Language Modeling from Scratch

https://cs336.stanford.edu/
246•kristianpaul•6h ago•34 comments

What appear to be biochemical processes may be a natural feature of geology

https://www.quantamagazine.org/the-dirt-that-refused-to-die-20260601/
143•speckx•5h ago•37 comments

GitHub and the crime against software

https://eblog.fly.dev/githubbad.html
113•pplanu•1h ago•37 comments

I made my phone slow on purpose

https://vinewallapp.com/notes/i-made-my-phone-slow-on-purpose/
127•gcampos•4d ago•108 comments

Ask HN: Who is hiring? (June 2026)

114•whoishiring•5h ago•172 comments

A 10 year old Xeon is all you need

https://point.free/blog/gemma-4-on-a-2016-xeon/
619•cafkafk•14h ago•252 comments

Anthropic confidentially submits draft S-1 to the SEC

https://www.anthropic.com/news/confidential-draft-s1-sec
335•surprisetalk•4h ago•255 comments

Nvidia RTX Spark

https://www.nvidia.com/en-us/products/rtx-spark/
229•shenli3514•15h ago•190 comments

Microsoft builds MacBook Pro rival with NVIDIA-powered Surface Laptop Ultra

https://www.windowslatest.com/2026/06/01/microsoft-builds-its-ultimate-macbook-pro-rival-with-the...
65•jbk•8h ago•214 comments

GrapheneOS Speech Services version 2 released

https://discuss.grapheneos.org/d/36001-grapheneos-speech-services-version-2-released
15•pretext•2h ago•2 comments

Stealing from Biologists to Compile Haskell Faster

https://www.iankduncan.com/engineering/2026-05-30-stealing-from-biologists-to-compile-haskell-fas...
40•mooreds•2d ago•2 comments

Windows GOG DOS Games on M-Series Macs

https://f055.net/technology/windows-gog-dos-games-on-m-series-macs/
111•f055•7h ago•65 comments

Launch HN: Expanse (YC P26) – Unlock Wasted GPU Capacity

60•ismaeel_bashir•7h ago•12 comments

Malicious npm packages detected across Red Hat Cloud Services

https://github.com/RedHatInsights/javascript-clients/issues/492
686•kurmiashish•7h ago•372 comments

Ask HN: Who wants to be hired? (June 2026)

57•whoishiring•5h ago•188 comments

Flipper Zero Zig Template

https://github.com/NishantJoshi00/flipper-template
108•Nars088•7h ago•7 comments

Only 17% of all 64-bit Integers are products of two 32-bit integers

https://lemire.me/blog/2026/05/22/only-17-of-all-64-bit-integers-are-products-of-two-32-bit-integ...
162•sebg•4d ago•79 comments

The Pirate Bay Remains Resilient, 20 Years After the Raid

https://torrentfreak.com/the-pirate-bay-remains-resilient-20-years-after-the-raid/
400•speckx•6h ago•195 comments

Superintelligence: The Idea That Eats Smart People (2016)

https://idlewords.com/talks/superintelligence.htm
76•thoughtpeddler•3h ago•83 comments

Sysadmining Like It's 2009

https://lambdacreate.com/posts/sysadmining-like-its-2009
74•yacin•6h ago•29 comments

Linux Basics for Hackers (2019)

https://github.com/ahegazy0/linux-basics-for-hackers-notes
98•ibobev•7h ago•19 comments

Handmade Hawaiian Islands Map

https://www.notesfromtheroad.com/roam/hawaiian-islands-map.html
30•bovermyer•2d ago•13 comments

Florida AG files lawsuit against OpenAI, CEO Sam Altman for deceptive practices

https://www.myfloridalegal.com/newsrelease/attorney-general-james-uthmeier-files-first-nation-sta...
33•benwen•2h ago•5 comments

Show HN: Textile – A desktop app for weaving together bits of text

https://www.gettextile.app
6•stack_framer•1h ago•1 comments

Show HN: A CSS 3D Engine (no WebGL)

https://github.com/LayoutitStudio/polycss
46•rofko•6h ago•20 comments