惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IT之家
IT之家
aimingoo的专栏
aimingoo的专栏
H
Help Net Security
L
LangChain Blog
M
MIT News - Artificial intelligence
The GitHub Blog
The GitHub Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
C
Check Point Blog
P
Proofpoint News Feed
J
Java Code Geeks
大猫的无限游戏
大猫的无限游戏
博客园_首页
Blog — PlanetScale
Blog — PlanetScale
U
Unit 42
I
InfoQ
月光博客
月光博客
爱范儿
爱范儿
Stack Overflow Blog
Stack Overflow Blog
V
Visual Studio Blog
Y
Y Combinator Blog
Microsoft Security Blog
Microsoft Security Blog
博客园 - Franky
D
Docker
B
Blog

Hackread – Cybersecurity News, Data Breaches, AI and More

Suspected Cyberattack Sends Fake Emergency Alert to Phones Across Brazil Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks New GhostShell Hacking Group Targets Ukraine’s Drone Defense Sector Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords Best Crypto Payment Solutions for E-Commerce Businesses Internet Society Foundation Opens Global Call for Common Good Cyber Fund to Strengthen Cybersecurity LastPass Confirms Customer Data Breach After Klue OAuth Token Theft ‘Cordyceps’ CI/CD Flaw Exposes Microsoft, Google, Apache Repos to Pipeline Hijacking The Rise of AI-Powered Academic Fraud: Beyond Traditional Plagiarism New CryptoBandits Malware Uses USB Drives and Tor to Steal Crypto The Evolution of iGaming Fraud: What Security Teams Should Expect in 2027 2 Scattered Spider-Linked Hackers Plead Guilty Over £39M TfL Cyberattack Beats Studio Buds Flaw Could Let Nearby Attackers Eavesdrop on Users Texas Parks and Wildlife Data Breach Affects Over 3M License Customers Threat Hunting Beyond Alerts: Finding the Activity Detection Misses Scammers Use Fake GitHub Stars, VirusTotal Reviews to Spread Crypto Clipper Salesforce Disables Klue Integration After OAuth Token Theft Hits Customer Data MDR Provider Comparison: Time to Discover and Respond to Threats Meteor 3.0 Migration Helped Rocket.Chat Move Off End-of-Life Node.js Runtime Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections Nintendo America Employee Data Exposed After Shadowbyt3$ Targets TinyPulse eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks FIFA World Cup 2026: Hackers Target Football Fans With Fake Tickets Sites MacBook Neo vs Windows Laptops for Cybersecurity Tasks Operation Endgame Disrupts SocGholish Malware Infrastructure What Businesses Should Know Before Migrating Their CMS DragonForce Ransomware Abused Microsoft Teams to Hide Malware Activity Agentjacking: Researchers Show How One Fake Bug Report Can Hijack AI Coding Agents FortiBleed Attack Exposes Fortinet Firewall Credentials in 194 Countries SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies
Instagram Glitch Reportedly Exposed Contact Info of Zucke...
Deeba Ahmed · 2026-06-08 · via Hackread – Cybersecurity News, Data Breaches, AI and More

An unexpected incident occurred on 6 June 2026 when, reportedly, a security flaw at Instagram briefly exposed private data of top users, including Meta head Mark Zuckerberg and several others.

The issue was reportedly found in Instagram’s website tool that people use when they forget their passwords and need to reset them. The exposed data included personal phone numbers and email addresses of the impacted personalities.

How the Leak Happened

Normally, when someone tries to reset a password, Instagram hides most of the contact details. For example, it might show an email as m***@fb.com to protect the owner.

However, a glitch in the website’s code stopped this hiding process from working. Anyone who typed in a username could see the full, real email addresses and phone numbers connected to that account.

Pictures showing the vulnerability working spread quickly on social media as several accounts shared images of Mark Zuckerberg’s login screen, which showed his private emails and phone number.

Meta is still having some minor security problems. Instagram is currently exposing phone numbers and email addresses associated with accounts when trying to perform a password reset

This is cool and badass because everyone is sharing Mark Zuckerbergs phone number right now

— vx-underground (@vxunderground) June 6, 2026

International Cyber Digest, a cybersecurity feed on X, posted about the flaw, which exposed football star Kylian Mbappé’s hidden TikTok account. The account was not publicly linked to his official identity or public brand.

Preliminary investigation revealed the issue was a logic bug, and there was no indication of hackers infiltrating Meta’s main servers to steal data. A logic bug means it was an error in how the website was programmed to think.

Meta hasn’t given the flaw an official CVE tracking name yet. However, experts say showing this data breaks Meta’s own rules and might break European GDPR Article 25 privacy laws.

Instagram Glitch Exposes Zuckerberg’s Contact Info and Other Top Users’ Details
Mark Zuckerberg and Kylian Mbappé’s contact information exposed

One X user criticized the company, writing that this newest leak “is what happens when you fire the experts and rely on brain-dead AI to run core infrastructure.”

Other Security Troubles

This isn’t the first safety issue for Instagram this year because in January 2026, there was another incident where scammers abused its password system to send out millions of fake emails. Around the same time, lists containing 17.5 million user records were allegedly leaked on dark web forums.

In another event this June, threat actors used prompt injection to trick Meta’s AI customer service chatbot. By feeding the AI confusing instructions, they hijacked top accounts, including pages for the White House archive and the US Space Force.

Regarding the Instagram password-reset flaw, Meta, Instagram’s owner, acted fast and implemented an emergency fix within a few hours to stop the leak. “We fixed an issue that allowed an external party to request password reset emails for some Instagram users. There was no breach of our systems,” the company released this statement.

However, there’s still a question mark over its data safety rules. While the company says no data was stolen en masse, exposure of these details brings bad consequences. Scammers can use full phone numbers and emails for phishing scams, SIM-swapping attacks to steal phone lines, or to identify a target’s other online accounts.