Accounts – Gaming Master https://gaming.vmondeika.com Get daily gaming updates with us Fri, 12 Jun 2026 09:42:47 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 WhatsApp’s new iPhone update makes juggling two accounts much less annoying https://gaming.vmondeika.com/whatsapps-new-iphone-update-makes-juggling-two-accounts-much-less-annoying/ https://gaming.vmondeika.com/whatsapps-new-iphone-update-makes-juggling-two-accounts-much-less-annoying/#respond Fri, 12 Jun 2026 09:42:47 +0000 https://gaming.vmondeika.com/whatsapps-new-iphone-update-makes-juggling-two-accounts-much-less-annoying/ [ad_1]

WhatsApp is finally making it easier to run two accounts on the same iPhone, which should cut down on the old workaround of keeping one number in WhatsApp Business or on another device.

Spotted by WABetaInfo, WhatsApp multiple accounts iPhone rollout is now widely available through version 26.22.76, after a slower release that didn’t reach everyone at once. Users can add a second number inside the main app, then keep chats, calls, alerts, and settings tied to the correct login.

For anyone splitting work and personal messages, the update makes WhatsApp feel less like a single crowded inbox and more like two controlled spaces.

How the new iPhone setup works

Setup starts in WhatsApp settings with the “Add account” option. From there, users can enter another phone number or scan a QR code to connect that login as a linked device.

Switching doesn’t require logging out. Users can open the Account section and tap “Switch account,” press and hold the You tab for a faster jump, or tap the You tab once to see which logins are already registered.

There’s still a ceiling. WhatsApp currently supports up to two accounts at a time on iPhone, so this solves the common two-number problem rather than turning the app into a full account manager.

Why the old workarounds faded

Before this rollout, iPhone users had clumsy options. They could put a second number in WhatsApp Business, even without business needs, or keep the other login on a different phone.

The new setup keeps the split inside one app. Chat history, calls, notification choices, privacy settings, profile information, and other preferences stay with their own profile. A custom alert tone on one number won’t carry over to the other.

WhatsApp also keeps watching the inactive login. When a message or call comes in there, the app can send a push notification, and the user can open that profile from the alert before responding.

When the feature reaches everyone

WhatsApp says multiple accounts are available to all users through the latest App Store version, with iOS 26.22.76 listed as a compatible update. Beta testers can also get the feature through the latest TestFlight build.

Anyone who doesn’t see it yet should update WhatsApp from the App Store and check settings for “Add account.” Removing a login from the device won’t delete groups or channels, but WhatsApp recommends backing up chats first because unbacked-up messages and data can be lost.

The practical move is simple enough. Update the app, add the second number, and let WhatsApp handle the split that used to require a workaround.

[ad_2]

Source link

]]>
https://gaming.vmondeika.com/whatsapps-new-iphone-update-makes-juggling-two-accounts-much-less-annoying/feed/ 0
Meta’s AI bot helped hackers steal Instagram accounts, and it was worryingly easy to trick https://gaming.vmondeika.com/metas-ai-bot-helped-hackers-steal-instagram-accounts-and-it-was-worryingly-easy-to-trick/ https://gaming.vmondeika.com/metas-ai-bot-helped-hackers-steal-instagram-accounts-and-it-was-worryingly-easy-to-trick/#respond Tue, 02 Jun 2026 06:09:53 +0000 https://gaming.vmondeika.com/metas-ai-bot-helped-hackers-steal-instagram-accounts-and-it-was-worryingly-easy-to-trick/ [ad_1]

Instagram has fixed a scary security flaw that allowed hackers to take over accounts using Meta’s own AI support chatbot. The issue came to light over the weekend, when multiple users on Reddit and X reported that their accounts had been compromised. 

Even my Instagram account got hacked

The password got changed without my knowledge and I was getting different password reset attempts throughout yesterday. And I got repeatedly logged out from the IG iOS app

Quite concerning https://t.co/F6wjKYrlBo

— Jane Manchun Wong (@wongmjane) June 1, 2026

As reported by TechCrunch, security researcher Jane Wong was also among those affected. “The password got changed without my knowledge, and I was getting different password reset attempts throughout yesterday,” she said. “Quite concerning.”

How did the hack work?

A video posted on X showed the entire process, and it’s alarming in how simple it was. The hacker first used a VPN to spoof the location, bypassing Instagram’s automated account protections. Then, they opened a chat with Meta’s AI Support Assistant and simply asked the bot to add a new email address to the target’s account.

🚨 Instagram had an exploit that allowed you to use Meta AI to reset passwords to accounts with no MFA on them. The exploit was patched a short time ago.pic.twitter.com/PEUwLvmllj

— Dark Web Informer (@DarkWebInformer) June 1, 2026

Here’s where it gets wild. The chatbot sent a verification code to the hacker’s email, not the victim’s. The hacker shared the code back with the chatbot, which then offered a button to reset the password. That’s how easy it was to take over the account of anyone on Instagram. 

TechCrunch verified that the hacker’s public email mailbox did receive the verification code, confirming the attack worked exactly as shown.

Is your account at risk?

The scariest part of this attack is that the hacker never needed access to the victim’s real email address at any point. The entire process bypassed the actual account owner completely.

Instagram spokesperson Andy Stone confirmed on Monday that the issue has now been fixed. However, it remains unclear how many users had their accounts compromised before the patch. So, the good news is that you don’t have to worry about this issue anymore.

The state of AI in support

The rising prices of consumer electronics, the growing ease with which fraudsters can deceive people, and the challenges universities face as students use AI to cheat are just some examples of how AI has made our lives worse.

For me, the most annoying application of AI is in support chats. I recently ordered dinner, which was delayed. The AI support chat didn’t let me talk to a human for about two hours, repeatedly telling me that the food would arrive in the next 10 minutes. 

Before this was implemented, any query I had was resolved in minutes by a human customer service agent. Meta’s AI support chatbot is yet another example of how allowing AI in customer service is creating unnecessary stress for users.

[ad_2]

Source link

]]>
https://gaming.vmondeika.com/metas-ai-bot-helped-hackers-steal-instagram-accounts-and-it-was-worryingly-easy-to-trick/feed/ 0
Hackers hijacked Instagram accounts by tricking Meta AI support chatbot into granting access https://gaming.vmondeika.com/hackers-hijacked-instagram-accounts-by-tricking-meta-ai-support-chatbot-into-granting-access/ https://gaming.vmondeika.com/hackers-hijacked-instagram-accounts-by-tricking-meta-ai-support-chatbot-into-granting-access/#respond Tue, 02 Jun 2026 04:16:16 +0000 https://gaming.vmondeika.com/hackers-hijacked-instagram-accounts-by-tricking-meta-ai-support-chatbot-into-granting-access/ [ad_1]

Instagram has resolved a security issue that allowed several users’ accounts to get hacked. The attack appeared to rely on tricking Meta’s own AI-powered support chatbot into granting access to a victim’s account.

Over the weekend, several users on Reddit claimed that their Instagram accounts had been compromised, and a number of users on X warned of similar account hijackings. The compromised accounts include the Instagram handle for the Obama-era White House, which appears to have been inactive since 2017; and the account of the U.S. Space Force’s chief master sergeant John Bentivegna.

Security researcher Jane Wong said her Instagram account was also taken over. 

“The password got changed without my knowledge and I was getting different password reset attempts throughout yesterday,” said Wong. “Quite concerning.” 

A video posted on X showed the step-by-step process to hack someone’s Instagram account. The hacker allegedly used a VPN to spoof the targets’ presumed location to avoid triggering Instagram’s automated account protections. Then, the hacker opened a chat with Meta AI Support Assistant and asked the bot to add a new email address to the target’s account. The chatbot can be seen sending a verification code to the email address provided by the hacker; the hacker then shares the verification code with the chatbot, which prompts the chatbot to show a button to “Reset Password.” The hacker enters a new password and takes over the victim’s account. 

Contact Us

Do you have more information about these Instagram hacks? Or other flaws affecting Instagram? We’d love to hear from you. From a non-work device and network, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email.

TechCrunch was able to verify that the hacker’s public email mailbox, which was displayed in the video, effectively received the verification code. 

The attack relied on the fact that at no point the hacker had to take over the legitimate email address linked to the victims’ Instagram account. 

On Monday, Instagram spokesperson Andy Stone said in a reply to Wong’s post and others that the issue was now fixed. It’s unclear how many Instagram users had their accounts improperly accessed.

Meta did not immediately respond to TechCrunch’s request for comment.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

[ad_2]

Source link

]]>
https://gaming.vmondeika.com/hackers-hijacked-instagram-accounts-by-tricking-meta-ai-support-chatbot-into-granting-access/feed/ 0
GTA V cheat service Atlas Menu hacked, 64,000 accounts exposed https://gaming.vmondeika.com/gta-v-cheat-service-atlas-menu-hacked-64000-accounts-exposed/ https://gaming.vmondeika.com/gta-v-cheat-service-atlas-menu-hacked-64000-accounts-exposed/#respond Tue, 02 Jun 2026 03:53:24 +0000 https://gaming.vmondeika.com/gta-v-cheat-service-atlas-menu-hacked-64000-accounts-exposed/ [ad_1]

TL;DR

Atlas Menu, a GTA V cheat service that promised “enhanced privacy,” was hacked, exposing nearly 64,000 accounts including emails, usernames, hashed passwords, and IP addresses. The stolen data was posted to GitHub by a hacker motivated by revenge.

Atlas Menu, a cheat service for Grand Theft Auto V’s online mode, has been hacked, exposing the personal data of nearly 64,000 users. The stolen data included email addresses, usernames, hashed passwords, IP addresses, and support tickets, according to data breach notification service Have I Been Pwned. The breach was claimed by a hacker whose stated motivation was revenge against a scammer, and the allegedly stolen data was posted publicly to GitHub.

The irony is difficult to miss. Atlas Menu marketed itself on security, promising users “secure authentication and enhanced privacy through our advanced encryption techniques,” according to its official website, which was archived before going offline. The service sold features that gave GTA V players unfair advantages: invisibility, super jumps, the ability to fly through the map, and other modifications to Rockstar Games’ online multiplayer environment.

A multi-million dollar shadow industry

Game cheats have evolved from hobbyist projects into a multi-million dollar commercial market. Professional and semi-professional gamers pay for software that provides advantages over competitors, while casual players use cheats to bypass progression systems or grief other users. Services like Atlas Menu operated in a legal grey area, selling tools that violate most games’ terms of service but are not themselves illegal in most jurisdictions.

The breach exposes users to potential embarrassment and further security risks. Email addresses tied to gaming accounts often overlap with primary personal accounts, meaning that users who signed up for a cheat service with the same credentials they use elsewhere now face credential-stuffing attacks. The hashed passwords provide some protection, but depending on the hashing algorithm used, determined attackers could crack weaker passwords.

Atlas Menu is not the first cheat service to be breached. A popular cheat service for Counter-Strike: Global Offensive was hacked several years ago in a similar incident. The GTA franchise has been a recurring target for security incidents, from the 2023 GTA VI trailer leak traced to a Rockstar developer’s son to repeated exploits targeting GTA Online’s peer-to-peer networking architecture.

The enforcement gap

The breach highlights a structural problem in gaming security. Cheat services operate with minimal accountability: their operators are often anonymous, their infrastructure is disposable, and their users have no recourse when things go wrong. Unlike enterprise software vendors that face regulatory and contractual obligations to protect customer data, cheat service operators answer to no one.

Rockstar Games has invested heavily in anti-cheat systems for GTA Online, but the persistence of services like Atlas Menu demonstrates the limits of technical enforcement against a motivated and commercially incentivised cheating ecosystem. Law enforcement has targeted some gaming-adjacent cybercrime operations, but cheat services rarely rise to the level of criminal prosecution unless they involve direct financial fraud or intellectual property theft at scale.

The owners of Atlas Menu could not be reached for comment. The site remains offline.

[ad_2]

Source link

]]>
https://gaming.vmondeika.com/gta-v-cheat-service-atlas-menu-hacked-64000-accounts-exposed/feed/ 0
WP Maps Pro WordPress flaw exploited to create admin accounts https://gaming.vmondeika.com/wp-maps-pro-wordpress-flaw-exploited-to-create-admin-accounts/ https://gaming.vmondeika.com/wp-maps-pro-wordpress-flaw-exploited-to-create-admin-accounts/#respond Tue, 02 Jun 2026 02:59:03 +0000 https://gaming.vmondeika.com/wp-maps-pro-wordpress-flaw-exploited-to-create-admin-accounts/ [ad_1]

TL;DR

A critical vulnerability (CVE-2026-8732, CVSS 9.8) in the WP Maps Pro WordPress plugin allows unauthenticated attackers to create admin accounts and take over sites. Wordfence blocked 2,858 exploitation attempts in 24 hours, with the flaw patched in version 6.1.1.

A critical vulnerability in WP Maps Pro, a commercial WordPress plugin with more than 15,000 sales on the Envato Market, is being actively exploited by attackers to create malicious administrator accounts on vulnerable sites. The flaw, tracked as CVE-2026-8732 with a CVSS score of 9.8, allows unauthenticated users to gain full administrative control of any WordPress installation running an unpatched version of the plugin.

Wordfence, which discovered the exploitation campaign, reported blocking 2,858 attacks targeting the vulnerability in the 24 hours prior to its disclosure. The flaw affects all versions of WP Maps Pro up to and including 6.1.0 and was patched in version 6.1.1, released on 20 May 2026. Security researcher David Brown is credited with discovering and reporting the issue.

How the exploit works

WP Maps Pro includes a “temporary access” feature designed to let the plugin’s support staff log into a customer’s site during troubleshooting. The feature exposes an AJAX action called “wpgmp_temp_access_ajax” that can create a new WordPress user with administrator privileges. The security architecture behind the feature was fundamentally flawed: the action was registered with WordPress’s “wp_ajax_nopriv_” hook, meaning it could be called by unauthenticated visitors.

The only protection was a nonce check, a token meant to prevent cross-site request forgery. But the nonce was publicly embedded into every frontend page of the site via the “wpgmp_local” JavaScript object, rendering it useless as an access control mechanism. Any visitor could read the nonce from the page source and use it to invoke the function.

The 💜 of EU tech

The latest rumblings from the EU tech scene, a story from our wise ol’ founder Boris, and some questionable AI art. It’s free, every week, in your inbox. Sign up now!

An attacker who calls the endpoint with the parameter “check_temp=false” triggers the “wpgmp_temp_access_support()” function, which unconditionally creates a new WordPress user with the hardcoded role of administrator and returns a magic login URL. Visiting that URL calls “wp_set_auth_cookie()” to fully authenticate the attacker as the newly created admin. The entire chain, from unauthenticated request to full site takeover, requires no credentials, no social engineering, and no prior access.

The plugin and its reach

WP Maps Pro allows site owners to embed customisable Google Maps and OpenStreetMap views with markers, listings, and advanced location features. It is commonly used as a store locator tool for businesses that need to help users find nearby locations, view details, and get directions. The plugin is sold through the Envato Market (CodeCanyon), not through WordPress’s official plugin directory, which means updates are not distributed through the standard WordPress auto-update mechanism.

That distribution model creates a particular risk. Site owners who purchased the plugin may not receive automatic notifications about the security update, and many WordPress installations are maintained by non-technical users or agencies that do not monitor vulnerability disclosures. Unlike large-scale cybercrime infrastructure that law enforcement can target with server seizures, WordPress plugin vulnerabilities are exploited through distributed, automated scanning campaigns that are difficult to disrupt.

What site owners should do

The patch in version 6.1.1 restricts the temporary access endpoint to authenticated administrators only. Site owners running WP Maps Pro should update immediately. Those who cannot update should disable the plugin until they can apply the patch. Checking for unexpected administrator accounts in the WordPress user list is a practical first step to determine whether a site has already been compromised.

The vulnerability is a textbook example of a pattern that recurs across the WordPress ecosystem: a support or debugging feature that grants elevated privileges, protected by a security mechanism that does not actually restrict access. Vulnerability disclosure programmes and security researchers like Brown play a critical role in catching these flaws before they cause widespread damage, but the 2,858 attacks blocked in a single day demonstrate that the window between disclosure and exploitation is now measured in hours, not weeks.

[ad_2]

Source link

]]>
https://gaming.vmondeika.com/wp-maps-pro-wordpress-flaw-exploited-to-create-admin-accounts/feed/ 0
Hackers hijacked Instagram accounts by asking Meta’s own AI chatbot to reset the password https://gaming.vmondeika.com/hackers-hijacked-instagram-accounts-by-asking-metas-own-ai-chatbot-to-reset-the-password/ https://gaming.vmondeika.com/hackers-hijacked-instagram-accounts-by-asking-metas-own-ai-chatbot-to-reset-the-password/#respond Tue, 02 Jun 2026 02:35:31 +0000 https://gaming.vmondeika.com/hackers-hijacked-instagram-accounts-by-asking-metas-own-ai-chatbot-to-reset-the-password/ [ad_1]

TL;DR

Hackers tricked Meta’s AI support chatbot into adding their email to victims’ Instagram accounts and resetting passwords. No victim email access needed.

Hackers hijacked Instagram accounts over the weekend by tricking Meta’s own AI-powered support chatbot into granting them access. The attack required no access to the victim’s email, no phishing link, and no malware. The hacker simply asked the chatbot to add a new email address to someone else’s account.

A video posted on X showed the step-by-step process. The hacker used a VPN to spoof the target’s presumed location, avoiding Instagram’s automated account protections. They then opened a chat with Meta AI Support Assistant and asked the bot to add a new email address to the target’s account.

The chatbot sent a verification code to the hacker’s email address. The hacker shared the code back with the chatbot. The bot then displayed a “Reset Password” button. The hacker entered a new password and took over the account.

The 💜 of EU tech

The latest rumblings from the EU tech scene, a story from our wise ol’ founder Boris, and some questionable AI art. It’s free, every week, in your inbox. Sign up now!

At no point did the hacker need to access the legitimate email address linked to the victim’s Instagram account. TechCrunch verified that the hacker’s public email mailbox, displayed in the video, received the verification code. The attack exploited a fundamental flaw: the AI chatbot treated the person it was talking to as the account owner without verifying their identity.

The compromised accounts included the Obama-era White House Instagram handle, which had been inactive since 2017, and the account of US Space Force Chief Master Sergeant John Bentivegna. Security researcher Jane Wong said her account was also taken over.

The password got changed without my knowledge and I was getting different password reset attempts throughout yesterday,” Wong said. “Quite concerning.” Multiple users on Reddit and X reported similar hijackings over the same weekend.

Instagram spokesperson Andy Stone said on Monday that the issue was fixed. It is unclear how many accounts were compromised. Meta did not respond to TechCrunch’s request for comment.

The attack is a textbook example of why deploying AI chatbots with account-level permissions is dangerous. Salesforce’s Agentforce customers have been reluctant to let AI agents take financially meaningful actions precisely because of this risk. Analyst Rebecca Wettemann described the fear as “the AI running off in the middle of the night and refunding a bunch of transactions.” Meta gave its AI the ability to reset passwords, and the AI did exactly what it was asked to do, for the wrong person.

The AI agent security landscape is producing new categories of vulnerability faster than companies can address them. OpenClaw’s Claw Chain exploit weaponised an agent’s own sandbox privileges. This Instagram attack weaponised an AI support bot’s account management privileges. The common thread: when an AI agent has the authority to act, the security of the system depends entirely on whether the agent can verify who is asking it to act.

The Meta AI Support Assistant was designed to reduce the cost of human customer service. It succeeded at that. It also created an attack surface that human support agents would not have: a human agent would have verified the caller’s identity before adding a new email to an account. The chatbot did not.

This is the third high-profile AI deployment failure in a single week. Starbucks scrapped its AI inventory system after nine months of miscounts. Waymo’s flood recall failed within two weeks. Meta’s AI chatbot gave hackers the keys to Instagram accounts. The pattern is consistent: AI systems deployed at scale fail in ways their designers did not anticipate, and the failures are more consequential than the efficiencies they were built to deliver.

[ad_2]

Source link

]]>
https://gaming.vmondeika.com/hackers-hijacked-instagram-accounts-by-asking-metas-own-ai-chatbot-to-reset-the-password/feed/ 0