---
title: "#AxisOfEasy 453: Instagram&#8217;s AI Chatbot Exploited To Hijack High-Profile Accounts"
type: "post"
post_id: "33982"
slug: "axisofeasy-453-instagrams-ai-chatbot-exploited-to-hijack-high-profile-accounts"
canonical: "https://axisofeasy.com/aoe/axisofeasy-453-instagrams-ai-chatbot-exploited-to-hijack-high-profile-accounts/"
markdown_url: "https://axisofeasy.com/aoe/axisofeasy-453-instagrams-ai-chatbot-exploited-to-hijack-high-profile-accounts.md"
json_url: "https://axisofeasy.com/aoe/axisofeasy-453-instagrams-ai-chatbot-exploited-to-hijack-high-profile-accounts.json"
txt_url: "https://axisofeasy.com/aoe/axisofeasy-453-instagrams-ai-chatbot-exploited-to-hijack-high-profile-accounts.txt"
published: "2026-06-05T22:00:22+00:00"
modified: "2026-06-11T14:15:35+00:00"
author: "Mark E. Jeftovic"
categories:
  - "#AxisOfEasy"
tags:
  - "account hijacking"
  - "Active Directory attacks"
  - "AI security"
  - "AI support assistant"
  - "AI-powered malware"
  - "Anthropic"
  - "automated malware testing"
  - "BitLocker"
  - "CI/CD compromise"
  - "claude mythos"
  - "cloud credentials"
  - "cloud infrastructure"
  - "cloud security"
  - "credential theft"
  - "critical infrastructure security"
  - "CrowdStrike"
  - "cyber espionage"
  - "Cybersecurity"
  - "data breach"
  - "easyClaw"
  - "easydns"
  - "EDR evasion"
  - "endpoint protection"
  - "exposed PII"
  - "financial records"
  - "Gemini vulnerability"
  - "Genesis ransomware"
  - "GitHub Actions secrets"
  - "healthcare data"
  - "identity theft"
  - "Instagram account takeover"
  - "IP exhaustion"
  - "Kubernetes credentials"
  - "malware development"
  - "Meta AI chatbot"
  - "Microsoft security researchers"
  - "npm malware"
  - "OpenClaw"
  - "phishing campaigns"
  - "Project Glasswing"
  - "ransomware"
  - "Red Hat npm compromise"
  - "responsible disclosure"
  - "Russian threat actors"
  - "Secure Boot"
  - "Shai-Hulud worm"
  - "SilentRunLoader"
  - "Slack integration"
  - "social engineering"
  - "Social Media Regulation"
  - "Sophos X-Ops"
  - "stock exchange compromise"
  - "supply chain attack"
  - "supply chain security"
  - "TeamPCP"
  - "third-party risk"
  - "threat intelligence"
  - "VPN spoofing"
  - "VPS hosting"
  - "vulnerability research"
  - "WhatsApp integration"
  - "Windows Defender"
  - "youth online safety"
  - "zero-day disclosure"
excerpt: "Instagram's AI Chatbot Exploited to Hijack High-Profile Accounts  Red Hat npm Channel Hijacked to Spread Credential-Stealing Worm  AI-Powered Malware Lab Targets Major EDR Platforms.. this and more in AofE  #453"
site_name: ""
publisher: ""
language: "en-US"
license: ""
generator: "easyPress AI Discoverability"
generator_version: "2.0.14"
---
*![](https://axisofeasy.com/wp-content/uploads/2020/02/weekly-briefing-axis-of-easy.jpg)*---

*Weekly Axis Of Easy #453*
==========================

---

***Last Week’s Quote was:** “Indecision and delays are the parents of failure,” was by George Canning. Stefan got it! Congrats 🙂  **This Week’s Quote:** “I do not know how to find out anything new without being offensive.” By ???

**THE RULES:** **No searching up the answer,** must be posted at the bottom of this blog post, in the comments section.*

*The Prize:*** *First person to post the correct answer gets their next domain or hosting renewal on us.*

 

 

---



*This is your easyDNS #AxisOfEasy Briefing for the week of June 1st, 2026. Our Technology Correspondent Joann L Barnes and easyCEO Mark E. Jeftovic send out a short briefing on the state of the ‘net and how it affects your business, security and privacy.

To Listen/watch this podcast edition with commentary and insight from Joey and Len the Lengend [click here.](https://axisofeasy.com/podcast/axisofeasy-453-instagrams-ai-chatbot-exploited-to-hijack-high-profile-accounts/)*

***In this issue:***

- **Instagram’s AI Chatbot Exploited to Hijack High-Profile Accounts**
- **Red Hat npm Channel Hijacked to Spread Credential-Stealing Worm**
- **AI-Powered Malware Lab Targets Major EDR Platforms**
- **IMA Diligence Services Data Breach Exposes 525,000+ Victims to Genesis Ransomware Group**
- **Microsoft Backs Down After Security Researcher Backlash**
 
***Elsewhere Online:***

- **Hackers Deploy New SilentRunLoader Malware in Tax Themed Phishing Campaigns**
- **Google Patches Flaw Allowing WhatsApp and Slack Messages to Control Gemini**
- **Senior Stock Exchange Executive Mailbox Compromised in Five Month Attack**
- **Anthropic Fights Zero Day Vulnerabilities by Expanding Project Glasswing**
- **California Proposes Social Media Ban for Youth to Combat Platform Addiction**
 
 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 



![](https://axisofeasy.com/wp-content/uploads/2026/05/easynode-launch-paused-resumed-1024x723.png)

[**easyClaw Launch Resumed**](https://get.easynode.ai/easyclaw)

After a big lead-up and much fanfare, we launched easyClaw – the hosted openclaw VPS in last week’s edition of AxisOfEasy

It was fun while it lasted, but at some point in the early hours of Saturday morning, we ran out of IPs and had to throw the brakes on sign-ups.

Sorry if you were one of the people affected.

We’ve since added more netblocks to the easyNode ecosystem, and we’re good to go.

Try *[easyclaw](https://get.easynode.ai/easyclaw)*

[**Instagram’s AI Chatbot Exploited to Hijack High-Profile Accounts**](https://techcrunch.com/2026/06/01/hackers-hijacked-instagram-accounts-by-tricking-meta-ai-support-chatbot-into-granting-access/)

Instagram patched a vulnerability in its Meta AI Support Assistant after hackers used the chatbot to hijack user accounts. Attackers spoofed victims’ locations via VPN, then tricked the bot into adding a hacker-controlled email to target accounts — receiving verification codes directly and resetting passwords without ever accessing victims’ legitimate email.

Compromised accounts included the Obama-era White House handle, U.S. Space Force Chief Master Sergeant John Bentivegna, and security researcher Jane Wong. Spokesperson Andy Stone confirmed the fix Monday; the number of affected users remains unknown.

Read: https://techcrunch.com/2026/06/01/hackers-hijacked-instagram-accounts-by-tricking-meta-ai-support-chatbot-into-granting-access/
*More via [Techcrunch](https://techcrunch.com/2026/06/01/hackers-hijacked-instagram-accounts-by-tricking-meta-ai-support-chatbot-into-granting-access/)*


**[Red Hat npm Channel Hijacked to Spread Credential-Stealing Worm](https://arstechnica.com/security/2026/06/dozens-of-red-hat-packages-backdoored-through-its-offical-npm-channel/)**

Threat actors compromised Red Hat’s official npm channel, @redhat-cloud-services, deploying the self-spreading worm Shai-Hulud across 30+ packages. Discovered by security firms Aikido and Socket, the malware executes during npm install, harvesting GitHub Actions secrets, npm tokens, and Kubernetes, Vault, and cloud credentials before self-propagating to accessible third-party accounts.

Stolen data is exfiltrated encrypted, with a GitHub repository fallback. The attack, traced to TeamPCP — who offered $1,000 for the largest supply-chain attack using the worm — entered via Red Hat’s compromised CI/CD pipeline. Red Hat confirmed no customer systems were affected.

Read: https://arstechnica.com/security/2026/06/dozens-of-red-hat-packages-backdoored-through-its-offical-npm-channel/
*More via[ Arstechnica](https://arstechnica.com/security/2026/06/dozens-of-red-hat-packages-backdoored-through-its-offical-npm-channel/)*


[**AI-Powered Malware Lab Targets Major EDR Platforms**](https://www.darkreading.com/endpoint-security/attackers-automate-edr-evasion-testing)

Sophos X-Ops researchers uncovered a Russian-linked threat actor running a sophisticated, hybrid human-AI malware development operation. Detected via malicious payloads in a customer tenant traced to a local test directory, the attack featured AI-generated Python scripts tied to an automated Active Directory panel.

The system iteratively built and tested malware against Sophos, CrowdStrike, and Windows Defender EDR tools, automatically cycling through predefined tasks and dispatching work to remote agents. Human reviewers refined results alongside AI automation, revealing a structured engineering approach purpose-built to defeat enterprise endpoint defenses.

Read: https://www.darkreading.com/endpoint-security/attackers-automate-edr-evasion-testing
*More via [Darkreading](https://www.darkreading.com/endpoint-security/attackers-automate-edr-evasion-testing)*


[**IMA Diligence Services Data Breach Exposes 525,000+ Victims to Genesis Ransomware Group**](https://www.securityweek.com/ima-diligence-services-data-breach-impacts-525000-people/)

IMA Diligence Services, a subsidiary of IMA Financial Group, has notified 525,306 individuals after the Genesis ransomware group infiltrated a third-party-managed legacy server between December 8–16, exfiltrating 700 GB of data. The breach, discovered in mid-December, exposed names, addresses, Social Security numbers, driver’s license numbers, account and credit card numbers, medical and health insurance details, and in some cases passport and taxpayer ID numbers. The company reported the incident to the Indiana Attorney General’s Office and is offering affected individuals 12 months of free credit monitoring and identity restoration services.

Read: https://www.securityweek.com/ima-diligence-services-data-breach-impacts-525000-people/
*More via [Securityweek](https://www.securityweek.com/ima-diligence-services-data-breach-impacts-525000-people/)*


[**Microsoft Backs Down After Security Researcher Backlash**](https://www.theregister.com/security/2026/06/02/microsoft-reaches-for-olive-branch-after-public-dustup-with-0-day-researcher/5249945)

Microsoft issued a damage-control statement Monday reversing its earlier threatening stance toward security researchers, declaring no intention of pursuing legal action. The reversal followed a feud with researcher Nightmare-Eclipse, who published multiple Windows zero-days with proof-of-concept exploits after claiming Microsoft deleted his reporting accounts, refused bounties, and mishandled communications.

Several vulnerabilities were exploited in the wild. The approach backfired when other researchers began supplying Nightmare-Eclipse additional flaws, including “Bitskrieg,” targeting Secure Boot and BitLocker. Microsoft declined to address any of his specific allegations.

Read: https://www.theregister.com/security/2026/06/02/microsoft-reaches-for-olive-branch-after-public-dustup-with-0-day-researcher/5249945
*More via [Theregister](https://www.theregister.com/security/2026/06/02/microsoft-reaches-for-olive-branch-after-public-dustup-with-0-day-researcher/5249945)*

---

***Elsewhere Online:***

**Hackers Deploy New SilentRunLoader Malware in Tax Themed Phishing Campaigns**
*Read: https://hackread.com/china-ta4922-hackers-uk-europe-silentrunloader-malware/*

**Google Patches Flaw Allowing WhatsApp and Slack Messages to Control Gemini**
*Read: https://thehackernews.com/2026/06/whatsapp-slack-notifications-could.html*

**Senior Stock Exchange Executive Mailbox Compromised in Five Month Attack** 
*Read: https://www.securityweek.com/hackers-target-global-stock-exchange-in-espionage-operation/*

**Anthropic Fights Zero Day Vulnerabilities by Expanding Project Glasswing** 
*Read: https://techcrunch.com/2026/06/02/anthropic-scales-claude-mythos-to-critical-infrastructure-in-15-countries/*

**California Proposes Social Media Ban for Youth to Combat Platform Addiction**
*Read: https://reclaimthenet.org/california-assembly-passes-under-16-social-media-ban*

---

**Previously on #AxisOfEasy**

If you missed the previous issues, they can be read online here:

- - - - - - - - - - [May 29th, 2026: Canada’s Bill C-22 Draws Global Tech Backlash Over Surveillance Demands](https://axisofeasy.com/352)
                                    - [May 22nd, 2026: Ontario Police Secretly Used Israeli Spyware, Watchdog Finds](https://axisofeasy.com/451)
                                    - [May 15th, 2026: Foxconn Hit by Nitrogen Ransomware, 8 TB of Client Data Stolen](https://axisofeasy.com/450)
                                    - [May 8th, 2026: Canada’s Parliament Is Filing Your Posts About Politicians](https://axisofeasy.com/449)
                                    - [May 1st, 2026: Toronto Police Bust Canada’s First SMS Blaster Cybercrime Operation](https://axisofeasy.com/448)
