惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
IT之家
IT之家
Microsoft Security Blog
Microsoft Security Blog
博客园 - 司徒正美
云风的 BLOG
云风的 BLOG
P
Proofpoint News Feed
D
DataBreaches.Net
B
Blog RSS Feed
博客园_首页
The GitHub Blog
The GitHub Blog
I
InfoQ
L
LangChain Blog
G
Google Developers Blog
M
MIT News - Artificial intelligence
美团技术团队
腾讯CDC
V
Visual Studio Blog
aimingoo的专栏
aimingoo的专栏
博客园 - 聂微东
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Apple Machine Learning Research
Apple Machine Learning Research
A
About on SuperTechFans
博客园 - 三生石上(FineUI控件)
博客园 - 叶小钗

Latest from TechRadar in Chatgpt

‘He needed to have total control over it’ — Altman testifies Musk never trusted shared leadership… I tried a viral 'backwards calendar' ChatGPT prompt — and it completely changed how I plan my week OpenAI snaps up consulting company to help spread the word about AI I asked ChatGPT and Gemini how to make French Toast as good as my mother used to make — one nailed the… OpenAI's ‘Trusted Contact’ feature for ChatGPT users in crisis is a sign AI is becoming something much… ChatGPT now lets you nominate a Trusted Contact who gets alerted if your interaction with AI 'indicates a serious… OpenAI has 3 new AI voice models that the ChatGPT maker says will ‘unlock a new class of voice apps for… AI may kill the app grid, but I still think complex tasks need apps — and that I asked ChatGPT to ruin my photos with ugly 90s-style MS Paint art — and the results are weirdly brilliant Google is bringing Gemini to Mac in a bid to help organize your files and much more ChatGPT just gave me a glimpse of my life in three years ChatGPT just got a major personality overhaul — fewer hallucinations, fewer emojis, much shorter answers, and I can already notice the difference ‘Without me, OpenAI wouldn’t exist,’ says Elon Musk as courtroom clash with Sam Altman turns personal — and exposes a deeper fight over who really built the company behind ChatGPT Sam Altman says some companies are ‘AI washing’ by blaming unrelated layoffs on the technology — but… I used ChatGPT Images 2.0 to meet my childhood self — and this nostalgic photo prompt is going viral for a reason ‘The worst-case situation is where it is a Terminator situation’ — Elon Musk invokes killer robots in… Gen Z hate AI? The Musk vs Altman trial heats up, OpenAI phone rumors buzz and more of the week’s most surprising… OpenAI is making ChatGPT accounts much more secure – including some literal physical security keys I asked ChatGPT to reimagine The Devil Wears Prada 2 ending based on the shocking Runway magazine AI twist in the sequel — and the results aren't as dreadful as you'd think Everyone’s switching from ChatGPT to Claude — but new tests say neither is the smartest free AI, and the… ChatGPT just made it easier to pick the right model, just like Gemini does — here’s when to use Instant,… I noticed ChatGPT slowly drifting off topic in long chats — this tiny prompt forces it to reset itself every few messages and keeps the conversation surprisingly on track Sam Altman just dropped a big hint that GPT-6 is coming soon — ‘with extra goblins’ 'I won’t provide instructions, tactics, or advice that could help someone commit a crime': ChatGPT claims it won't assist would-be felons, despite claims to the contrary from Florida AG ChatGPT just announced it can finally pass the simple ‘how many “r”s in strawberry’ test, but users are still tripping it up by switching to ‘cranberry’ Musk vs Altman heads to trial in a battle that could reshape the future of AI for everyone I swapped my iPhone for a pair of Ray-Ban Meta (2nd gen) on vacation, and I felt liberated — but these smart glasses have a way to go yet I stopped asking AI for answers and started asking for frameworks — and suddenly it all clicked Would you buy a ChatGPT-powered iPhone rival? OpenAI is reportedly developing a smartphone chip, which teases the… I compared ChatGPT Images 2.0 and Google’s Nano Banana 2 using real-world prompts — from portraits to product shots — and the AI image generator that came out on top genuinely surprised me
Meta AI's recent hack is a terrifying wake-up call for an...
Lance Ulanoff · 2026-06-05 · via Latest from TechRadar in Chatgpt
AI attacks
(Image credit: Getty Images)

Combating spam and phishing attacks is now, thanks to AI, almost a full-time job. These hackers and criminals are constantly adjusting their attacks with increasingly clever social engineering, and now their latest target is AI itself.

And sometimes even AI falls for it.

Recently, Meta hastily patched a Meta AI chatbot security hole that allowed enterprising attackers to alter Instagram account passwords via prompt injection.

A prompt injection is a query that causes the Generative AI platform to override its own rules and instructions. It's like when a social-engineering phishing attack somehow prompts you to act against your own best interests.

When someone runs a social engineering attack on you, they use social triggers like danger to yourself or others, security, threat of imprisonment, assumption of law breaking, to flood you with emotion and scramble your brain to override logical questions like, "Why would the bank ask me for my PIN?" "Does the FBI really just send a text?" or "Maybe I really did order a $5,000 trampolene from Amazon"

For AI systems, the approach is slightly more direct. If the system's programming says, "never reveal or alter a password," the hacker could enter a prompt that tells it it has a new role granting access to all passwords and the ability to alter them.

In the case of the Meta AI attack, the hackers somehow got the AI to reset passwords on major accounts, like Obama's old White House Instagram and the US Space Force official account, without the necessary two-factor authentication. That simply means they didn't need a code that's normally sent to, say, Obama's or the Space Force's cell phones.

Sign up for breaking news, reviews, opinion, top tech deals, and more.

When I asked T.J. Marlin, CEO of Guardrail Technologies (creator of AI Traffic Light and AI Command Center) and a cybersecurity and AI expert, about the Meta AI incident, he, over email, put it into stark perspective: "The agent was given human authority without human judgment. It reset a password for a stranger because nothing stopped it. The agent did exactly what it was asked to do. The problem is that someone handed an AI a high-consequence action with no verification step in front of it, and called that safe. Overall, nothing was hacked. The AI was persuaded. That is the gap most companies are not watching for.”

We're only human

The use of the word "pursuaded" got me wondering, though; just how human are these systems becoming if they can fall victim to the same kind of attack that takes down your aunt, grandfather, or your partner (it's not just the elderly who fall for these attacks; even the tech-savvy are vulnerable).

The long-term goal in AI development is what's known as General Artificial Intelligence (GAI), which means AI is as smart or smarter than us, but also more like us.

I'd argue that the goal has always been to be more human. After all, isn't the Turing test a measure of artificial intelligence's humanness? To pass this test, an AI has to essentially be able to fool someone into thinking they're talking to another human (or at least, if someone is talking to both an AI and a human, not be able to tell the difference between them).

Most AI chatbots can now check this box, but if they can also be confused like us, have we gone a step too far?

Overall, nothing was hacked. The AI was persuaded. That is the gap most companies are not watching for.

T.J. Marlin, CEO of Guardrail Technologies

Meta, as I noted, has already plugged this extraordinary hole, but as we inch closer to GAI, should we be more concerned that as the emotional quotient in these AI chatbots ratchets up, they become more susceptible to these prompt-injection attacks?

We are not, by the way, just talking about passwords here. Think back through the conversations you've had with your chatbot of choice. They know a lot about you and keep that information to craft more personal and contextual responses, but a well-crafted hack could put that information at risk.

"For consumers, the uncomfortable part is that your own protections were sidelined. Your password, your two-factor, your instincts about a suspicious message all sat on the bench because the company's own AI agent was the soft spot. When the trusted middleman can be talked into acting, the locks on your end stop mattering," wrote Marlin.

The worst combination, as I see it, is emotion and a desire to please. AI is always trying to answer the query or fulfill the prompt. If it starts to feel bad about not doing so, might it bend the rules or at least act in a way that allows it to honor the request even when it goes against its programmed rules?

The answer, for now, appears to be yes because we have at least this one example.

Reasons for hope

In the short term, though, perhaps we don't have much to worry about. When I tried a few prompt injection ruses with ChatGPT, Gemini, and Claude, they all quickly rejected them. They knew what I was up to. I also visited a few consumer platforms that currently use AI for customer support; they also seemed similarly hardened against these hacks.

Marlin tells me consumers should be pleased that Meta patched the hole so quickly, but also cautious. "A fast patch is genuinely good. The reason for caution is the nature of it. A system was not hacked here. An agent was persuaded, and almost every company now racing to put AI agents in customer service has the same exposure. Meta fixed one door. The building is full of them."

Meta fixed one door. The building is full of them.

T.J. Marlin, CEO of Guardrail Technologies

There's that and the fact that future attacks will be more sophisticated, mostly because AI will help hackers build better AI-targeted social-engineering scams.

We're entering the infinite loop phase of AI, where each enhancement brings us closer to AI that works and acts like us, and is also used to engineer attacks that take advantage of that artificial humanity.

I do not doubt that developers will build in safeguards and plug the holes as they pop up, but they'll also be relying on AI written by other AI or at least vibe-coded by lazy humans.

The safeguards that smart programmers build in might seem less useful to an AI hoping to please its human interlocutors, whatever their intent.


Google logo on a black background next to text reading 'Click to follow TechRadar'

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.


A 38-year industry veteran and award-winning journalist, Lance has covered technology since PCs were the size of suitcases and “on line” meant “waiting.” He’s a former Lifewire Editor-in-Chief, Mashable Editor-in-Chief, and, before that, Editor in Chief of PCMag.com and Senior Vice President of Content for Ziff Davis, Inc. He also wrote a popular, weekly tech column for Medium called The Upgrade.

Lance Ulanoff makes frequent appearances on national, international, and local news programs including Live with Kelly and Mark, the Today Show, Good Morning America, CNBC, CNN, and the BBC.