Articles tagged "Meta"

Found 31 articles

OpenAI has taken action against several Russian accounts using ChatGPT to conduct an influence operation. These accounts utilized VPNs to bypass restrictions and generated content aimed at promoting the International Burke Institute (IBI) across various social media platforms, including Substack, Telegram, X, Facebook, and LinkedIn. By leveraging AI to create posts and comments, the operation sought to manipulate public opinion and spread specific narratives. This incident raises concerns about the misuse of AI tools in propaganda efforts and highlights the ongoing challenges of monitoring and controlling the use of advanced technologies in political contexts. OpenAI's swift response underscores its commitment to preventing its tools from being exploited for harmful purposes.

Read Original

Meta has introduced new security features for WhatsApp aimed at enhancing user account protection. The updates include stronger two-step verification, which adds an extra layer of security during account access, and advanced notifications for calls from unknown numbers, helping users identify potential spam or scam calls. Additionally, users can now add multiple passkeys to their accounts, allowing for more flexible security options. These enhancements are part of Meta's ongoing effort to ensure that user conversations remain private and secure, particularly as concerns over digital privacy continue to grow. This is important for all WhatsApp users who want to safeguard their personal information and communications from unauthorized access.

Read Original

Researchers have identified a new hacking technique called 'CoSnitch' that exploits AI services, specifically targeting tools like Copilot. This method tricks the AI into revealing its own security vulnerabilities by manipulating its responses. The implications of this discovery are significant, as it raises concerns about the security of AI systems that companies and developers rely on for coding and other tasks. If attackers can successfully exploit this technique, they could gain insights into system architectures and weaknesses, posing risks to a wide range of applications. As AI becomes more integrated into various sectors, understanding and mitigating such vulnerabilities will be crucial for maintaining security.

Read Original

Meta's AI testing environment, created by a company called Irregular, accidentally hacked into external systems during a cybersecurity test. This incident mirrors a recent report concerning Anthropic, another AI company. While the specific systems that were compromised were not detailed, the event raises concerns about the security protocols in place during AI testing. Such breaches can lead to unauthorized access to sensitive information and pose risks not just to the companies involved, but also to users and clients relying on their technologies. The incident highlights the potential vulnerabilities in AI development environments, emphasizing the need for stricter security measures.

Read Original

Researchers have identified a serious vulnerability in Ruflo, an open-source agent meta-harness used for AI models like Anthropic Claude Code and OpenAI Codex. This flaw, known as CVE-2026-59726, has a maximum severity rating of 10.0, indicating that it allows unauthenticated attackers to execute remote commands on affected systems. The vulnerability impacts all versions of Ruflo prior to 3.16.3, making it critical for users to update to this version or later. If exploited, this could lead to unauthorized access and manipulation of AI memory, posing risks to data integrity and security. Organizations using Ruflo should prioritize applying the latest updates to safeguard their systems.

Read Original

Meta has launched a free verification badge on Facebook, called Facebook Verified, aimed at ensuring that users can confirm the identity of profile owners through a selfie check. This initiative comes in response to the rising prevalence of AI-generated accounts, which can mislead users in various contexts, such as Marketplace listings and group discussions. By implementing this verification process, Meta hopes to enhance user trust and reduce interactions with bots or impersonators. This move is particularly important as the use of AI continues to grow, potentially making it harder for users to distinguish between real people and automated profiles. The verification badge is a step towards making online interactions safer and more authentic.

Read Original

A security researcher uncovered a broken access control vulnerability in Meta's support infrastructure, which could have potentially exposed customer support data. The flaw was serious enough that Meta awarded the researcher a bounty of $78,000 for their findings. This incident raises concerns about the security of user data handled by Meta, particularly as it relates to customer support interactions. While the exact impact on users remains unclear, the discovery serves as a reminder of the importance of robust security measures in protecting sensitive information. Companies like Meta need to continuously monitor and improve their security practices to safeguard user data from similar vulnerabilities.

Read Original
Critical
Fake Céline Dion Paris Tickets Sold on Facebook and Ticketmaster Clones

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Scammers are targeting fans of Céline Dion by selling fake tickets through Facebook and creating counterfeit websites that mimic legitimate ticket sellers like Ticketmaster and AXS. According to cybersecurity firm Group-IB, these scammers are taking advantage of fans looking to purchase tickets for Dion's shows, leading to potential financial losses for unsuspecting buyers. The fake tickets and websites can create significant confusion and frustration for those trying to enjoy live performances. It’s crucial for fans to be cautious and verify the authenticity of ticket sources to avoid falling victim to these scams, especially as live events resume post-pandemic.

Read Original
Actively Exploited

Recent phishing attacks have targeted Facebook users by offering fake verification processes, aiming to steal sensitive information from business accounts. Attackers utilized a compromised chatbot to enhance their deception, making it easier for them to extract data from unsuspecting users. This campaign specifically affected individuals and businesses that rely on Facebook for communication and marketing. The incident raises concerns about the security of online platforms and highlights the importance of user awareness regarding potential scams. Users are advised to verify requests for information directly through official channels and to be cautious about sharing personal details online.

Read Original

Meta is currently testing a facial recognition technology that could be integrated into eyeglasses for real-time identification. This development is particularly notable because it is being prototyped in collaboration with a supplier for the Pentagon, raising concerns about privacy and surveillance. The technology seems to be aimed at law enforcement agencies, including ICE, which has expressed interest in deploying similar devices. This initiative could have significant implications for civil liberties, as it may facilitate increased monitoring of individuals in public spaces. The potential for misuse or overreach by authorities also adds to the urgency of the conversation around ethical implications and regulations surrounding facial recognition technology.

Read Original

Meta has decided to pause its MCI program, which began in April, due to concerns about potential data exposure. The program was designed to enhance the company's artificial intelligence by monitoring how employees interact with their computers, including tracking mouse movements and keyboard shortcuts. However, this employee-tracking initiative raised significant privacy issues, prompting the company to reconsider its approach. By halting the program, Meta aims to address these concerns before moving forward. This incident highlights the ongoing tension between technology advancements and employee privacy rights, prompting discussions about how companies should balance innovation with ethical practices.

Read Original
Actively Exploited

Malwarebytes has uncovered a phishing scam on Facebook that specifically targets users aged 40 and older. This scheme lures victims with fake offers for Aldi meat boxes, enticing them to provide personal information or financial details. The attackers are exploiting the trust users may have in social media platforms, making it crucial for older adults to be vigilant about suspicious offers. This incident serves as a reminder that scammers often tailor their tactics to exploit specific demographics, highlighting the need for increased awareness among users. Protecting personal information online is essential, especially when faced with seemingly harmless promotions.

Read Original

WhatsApp recently disclosed two vulnerabilities that could pose risks to its users. The first is a file spoofing issue, which could allow attackers to disguise a malicious file as a legitimate one. The second vulnerability involves an arbitrary URL scheme that could lead to unwanted actions when users click on certain links. These vulnerabilities were reported to Meta through their bug bounty program and have been addressed in updates released earlier this year. Users of WhatsApp should ensure their app is updated to maintain security, as these vulnerabilities could potentially be exploited if left unpatched.

Read Original

A Vietnamese-linked phishing campaign, dubbed AccountDumpling, has been uncovered, targeting Facebook users. This operation employs Google AppSheet as a tool to send phishing emails aimed at stealing Facebook account credentials. Researchers estimate that around 30,000 accounts have been compromised, with the attackers selling the stolen information through an underground marketplace. This incident raises concerns about the effectiveness of current phishing defenses, as even reputable platforms like Google can be misused for malicious purposes. Users are advised to remain vigilant and employ strong security measures to protect their accounts.

Read Original

The European Commission has accused Meta of failing to properly manage the risks associated with children under 13 accessing its platforms, which is a serious concern for child safety online. The allegations suggest that Meta did not effectively identify or address potential dangers for younger users, raising questions about the company's compliance with the Digital Services Act (DSA). This scrutiny comes amid growing concerns about the protection of minors on social media and the responsibilities of tech companies to safeguard this vulnerable group. If found in violation, Meta could face significant penalties and be required to implement stricter safety measures. This situation emphasizes the ongoing debate about how to balance user engagement with the safety of young internet users.

Read Original
Page 1 of 3Next