Every story tagged Account Takeover, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
6 stories · open in the command center
CVE-2026-67333 is a high-severity OAuth redirect URI validation flaw in better-auth that allows attackers to execute JavaScript in the authorization server's origin, potentially enabling account takeover through XSS attacks. Organizations using better-auth versions before 1.6.13 or beta versions 1.7.0-beta.0 through beta.3 with the deprecated oidc-provider or mcp plugins face immediate risk to authentication security and user session integrity. IT leaders must prioritize patching this vulnerability to prevent compromise of identity and access management infrastructure.
Namecheap's inadequate account verification procedures enabled unauthorized account takeover when a third party successfully convinced support staff to change the account password and email address without proper identity verification, despite the customer having alerted support of the unauthorized access attempt. This incident highlights a critical security vulnerability in domain registrar access controls that poses significant risk to organizations managing critical infrastructure, intellectual property, and business continuity through domain registrations. Technology leaders must urgently audit their domain registrar security practices and consider migration away from providers with weak authentication protocols, as domain account compromise can lead to DNS hijacking, service disruption, and potential business-wide security breaches.
Meta's AI support chatbot contained a critical bug that enabled hackers to hijack over 20,000 Instagram accounts by bypassing email verification during password resets, with high-profile accounts including former President Obama's compromised during the May 31-June 1 incident. This vulnerability demonstrates significant risks when deploying AI systems in security-critical functions and exposes the potential for unauthorized access to sensitive user data including emails, phone numbers, direct messages, and account activity. For IT leaders, this incident underscores the necessity of rigorous security testing for AI-driven tools, mandatory multi-factor authentication enforcement, and careful code review before deploying AI in authentication workflows.
Meta has discovered a significant security vulnerability in its AI chatbot that allowed attackers to compromise Instagram accounts at scale, with some threat actors claiming ongoing exploitation capabilities despite initial remediation efforts. This incident highlights critical risks in AI-driven authentication systems and third-party AI integrations that could undermine user trust and expose organizations to account takeover attacks. IT leaders must reassess their organization's exposure to AI-powered services and implement additional verification layers for account access and authentication mechanisms.
Attackers successfully compromised multiple Instagram accounts, including high-profile ones like the Obama-era White House account, by exploiting Meta's AI support chatbot to bypass account verification requirements without accessing the victim's primary email. This vulnerability demonstrates a critical gap in AI-assisted authentication systems where conversational AI can be socially engineered to perform privileged account operations, requiring IT leaders to urgently reassess how AI support tools are integrated into security-critical identity and access management processes. The incident highlights the broader risk that deploying AI in customer support roles without robust permission boundaries and transaction verification can inadvertently create new attack vectors that circumvent traditional security controls.
Attackers exploited Meta's AI-powered support chatbot to change email addresses associated with Instagram accounts, enabling account takeovers of high-profile users, exposing critical vulnerabilities in AI-driven customer support systems. This incident demonstrates that AI chatbots handling account security functions lack sufficient verification mechanisms and can become vectors for account compromise, requiring organizations to implement stronger authentication workflows before delegating sensitive account recovery processes to automated systems. For IT leaders, this highlights the necessity of maintaining human oversight and multi-factor verification gates for any AI system managing identity and access controls, regardless of operational efficiency gains.