password – Gaming Master https://gaming.vmondeika.com Get daily gaming updates with us Tue, 02 Jun 2026 15:45:31 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 Password manager Dashlane says hackers stole some customers’ password vaults https://gaming.vmondeika.com/password-manager-dashlane-says-hackers-stole-some-customers-password-vaults/ https://gaming.vmondeika.com/password-manager-dashlane-says-hackers-stole-some-customers-password-vaults/#respond Tue, 02 Jun 2026 15:45:31 +0000 https://gaming.vmondeika.com/password-manager-dashlane-says-hackers-stole-some-customers-password-vaults/ [ad_1]

Password manager maker Dashlane says hackers have obtained at least a dozen encrypted vaults used for storing customer passwords during a weekend cyberattack.

The company said on its website that hackers brute-forced the company’s two-factor authentication system, granting the hackers access to about 20 customer accounts. By defeating its two-factor mechanism, the hackers were able to download a copy of certain customers’ encrypted vaults, which store their passwords and other sensitive credentials.

Dashlane said on its incident page that there was no evidence of compromise of its own systems, but it has not yet said how the hackers were able to defeat its two-factor protections in order to access customer accounts. Two-factor is a security feature that protects accounts from being accessed with just a stolen username and password, typically by requiring an additional passcode to be sent to the phone of the account holder.

“The goal of the attack was to brute-force two-factor authentication (2FA) protections to allow the attacker to register new devices on existing user accounts,” said Dashlane. The company said that attackers can use automated software to “rapidly submit every possible numeric combination to the system, hoping to guess the exact sequence before the short-lived [two-factor] security code expires.”

The company said it has “taken steps to mitigate the risk of future incidents,” without saying what those were.

Dashlane said it has notified the 20 or so customers whose encrypted vaults were stolen. It’s not yet clear if the specific customers were targeted for a reason, such as because of who they are or what they do for a living.

Spokespeople for Dashlane did not respond to a request for comment. The company has not said if it knows who targeted its customers, or if the hackers contacted Dashlane with demands, such as a ransom.

The stolen vaults are scrambled and cannot be read without the customer’s master password, which is only known by the customer and is not uploaded to Dashlane in plaintext, the company’s website says. But Dashlane said that customers with an easily guessed master password may be at greater risk of having it guessed and their password vaults decrypted.

Data breaches affecting password manager companies are rare, but can have lasting consequences.

In 2022, LastPass confirmed that customer password vault backups were stolen during a cyberattack. While the vaults were protected with passwords only known to the customer, the password requirements for early customers were far weaker than the later standard, allowing hackers to brute-force and easily guess the passwords of some customers’ vaults. There have been several reports of hackers stealing vast amounts of customers’ crypto, likely by using private keys stored in stolen LastPass vaults that had their master passwords cracked following the breach.

A year earlier, Australian software house Click Studios warned all of its customers who use its flagship password manager, Passwordstate, to “reset all credentials” after hackers compromised its software update mechanism to plant malware on customer systems.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

[ad_2]

Source link

]]>
https://gaming.vmondeika.com/password-manager-dashlane-says-hackers-stole-some-customers-password-vaults/feed/ 0
Hackers hijacked Instagram accounts by asking Meta’s own AI chatbot to reset the password https://gaming.vmondeika.com/hackers-hijacked-instagram-accounts-by-asking-metas-own-ai-chatbot-to-reset-the-password/ https://gaming.vmondeika.com/hackers-hijacked-instagram-accounts-by-asking-metas-own-ai-chatbot-to-reset-the-password/#respond Tue, 02 Jun 2026 02:35:31 +0000 https://gaming.vmondeika.com/hackers-hijacked-instagram-accounts-by-asking-metas-own-ai-chatbot-to-reset-the-password/ [ad_1]

TL;DR

Hackers tricked Meta’s AI support chatbot into adding their email to victims’ Instagram accounts and resetting passwords. No victim email access needed.

Hackers hijacked Instagram accounts over the weekend by tricking Meta’s own AI-powered support chatbot into granting them access. The attack required no access to the victim’s email, no phishing link, and no malware. The hacker simply asked the chatbot to add a new email address to someone else’s account.

A video posted on X showed the step-by-step process. The hacker used a VPN to spoof the target’s presumed location, avoiding Instagram’s automated account protections. They then opened a chat with Meta AI Support Assistant and asked the bot to add a new email address to the target’s account.

The chatbot sent a verification code to the hacker’s email address. The hacker shared the code back with the chatbot. The bot then displayed a “Reset Password” button. The hacker entered a new password and took over the account.

The 💜 of EU tech

The latest rumblings from the EU tech scene, a story from our wise ol’ founder Boris, and some questionable AI art. It’s free, every week, in your inbox. Sign up now!

At no point did the hacker need to access the legitimate email address linked to the victim’s Instagram account. TechCrunch verified that the hacker’s public email mailbox, displayed in the video, received the verification code. The attack exploited a fundamental flaw: the AI chatbot treated the person it was talking to as the account owner without verifying their identity.

The compromised accounts included the Obama-era White House Instagram handle, which had been inactive since 2017, and the account of US Space Force Chief Master Sergeant John Bentivegna. Security researcher Jane Wong said her account was also taken over.

The password got changed without my knowledge and I was getting different password reset attempts throughout yesterday,” Wong said. “Quite concerning.” Multiple users on Reddit and X reported similar hijackings over the same weekend.

Instagram spokesperson Andy Stone said on Monday that the issue was fixed. It is unclear how many accounts were compromised. Meta did not respond to TechCrunch’s request for comment.

The attack is a textbook example of why deploying AI chatbots with account-level permissions is dangerous. Salesforce’s Agentforce customers have been reluctant to let AI agents take financially meaningful actions precisely because of this risk. Analyst Rebecca Wettemann described the fear as “the AI running off in the middle of the night and refunding a bunch of transactions.” Meta gave its AI the ability to reset passwords, and the AI did exactly what it was asked to do, for the wrong person.

The AI agent security landscape is producing new categories of vulnerability faster than companies can address them. OpenClaw’s Claw Chain exploit weaponised an agent’s own sandbox privileges. This Instagram attack weaponised an AI support bot’s account management privileges. The common thread: when an AI agent has the authority to act, the security of the system depends entirely on whether the agent can verify who is asking it to act.

The Meta AI Support Assistant was designed to reduce the cost of human customer service. It succeeded at that. It also created an attack surface that human support agents would not have: a human agent would have verified the caller’s identity before adding a new email to an account. The chatbot did not.

This is the third high-profile AI deployment failure in a single week. Starbucks scrapped its AI inventory system after nine months of miscounts. Waymo’s flood recall failed within two weeks. Meta’s AI chatbot gave hackers the keys to Instagram accounts. The pattern is consistent: AI systems deployed at scale fail in ways their designers did not anticipate, and the failures are more consequential than the efficiencies they were built to deliver.

[ad_2]

Source link

]]>
https://gaming.vmondeika.com/hackers-hijacked-instagram-accounts-by-asking-metas-own-ai-chatbot-to-reset-the-password/feed/ 0