Robin’s Newsletter #416

7 June 2026. Volume 9, Issue 23
Meta chatbot allowed Instagram account takeover. Anthropic expands Mythos access. Open source models used to create self-propagating, evolving malware
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

Infosecurity Europe 2026 was a blast — thanks to those of you who came to say hi — here’s my roundup video.

Need to Know, 7th June 2026

  • Meta’s chatbot used to hijack Instagram accounts
  • Anthropic expands Project Glasswing access
  • Open source AI models used to create self-propagating, evolving malware
  • Twenty Dashlane password vaults stolen during API brute force attack

Interesting stats

31% of breaches now start with software vulnerabilities, rather than stolen passwords, and 48% of all breaches now involve ransomware, though payouts are shrinking, while  40% higher click rates on mobile devices make them more attractive for phishing attempts than desktop clients, according to Verizon

Four things

  1. Meta’s AI support chatbot allowed attackers to takeover high profile Instagram accounts associated with the Obama White House and US Space Force, amongst others last weekend, and deface them with pro-Iranian propaganda. Two factors are at play here. Firstly, using a VPN to obtain an IP address near the victim’s normal location. Secondly, and perhaps more bizarrely, the chatbot would happily associate a new email address with the account, which can then be used to reset the password. We’ve seen a growing number of examples of AI chatbots being coerced into doing things they aren’t intended to do (like Chipotle’s being used for coding). However, chatbots are ultimately just API wrappers, which suggests that, in this case, policy enforcement is not handled in Meta’s APIs themselves, or that the chatbot can otherwise circumvent security layers.

  2. Anthropic has had a busy week. Mythos access has expanded to more than fifteen countries. Around 150 organisations now have access to the model under Project Glasswing, where the Claude maker says “a successful attack on their codebase could be catastrophic,” and “we estimate that a major attack could affect more than 100 million people, with important ramifications for both global and national security.” The UK’s Prudential Regulation Authority says that AI cyber risk is ‘top of the list’ of threats. Outgoing PRA CEO Sam Woods told the FT that the likes of Mythos require banks to undertake a significant “reordering [of] their tech programmes to make space for all this,” while also identifying higher-risk software components.  In addition to filing paperwork for a potential IPO, Anthropic also suffered a string of outages (see Incidents below).

  3. AI Malware: Meanwhile, researchers at the University of Toronto have published research that advanced models, like Mythos or OpenAI’s GPT 5.5-Cyber, are not needed to cause issues. They’ve used free open source models to create self-propagating code that can exploit known vulnerabilities and misconfigurations. The ‘parasitic’ worm uses the infected device’s compute to run the model and propagate itself, rendering centralised guardrails and controls irrelevant. The full report (PDF) contains a lot of preamble about the ethical considerations here.

  4. Dashlane says that its system managed to detect and mostly contain a large brute force campaign to obtain users’ password vaults. Getting access to these vaults is obviously attractive to threat actors, as it could allow them to access all of a user’s accounts. The attackers “targeted the API endpoints for device registration” with a “large volume of automated requests”. In 20 cases, they generated a valid token, allowing them to download the user’s encrypted vault. Unless the attackers have the user’s master password, it’s very unlikely they’ll be able to decrypt its contents.

In brief

And finally

  • The US  may have been using GPS satellites as a ‘numbers station’ to communicate secret codes to assets around the globe for nearly 20 years. The GPS specification includes a 176-bit data field — “Subframe 4, Page 17” — that drew the attention of security researcher Steven Murdoch, who was suspicious of the data’s randomness. Numbers stations, traditionally broadcast on shortwave radio, are used by intelligence agencies to communicate with people in circumstances where direct contact would be risky.
Robin
  Artificial Intelligence (AI) Meta Malware Brute Force API Chips Act 2.0 Cloud and AI Development Act (CADA) GPS Numbers station