Key developments
Meta Instagram recovery bug exposed 20,225 accounts
Meta disclosed that a flaw in Instagram's AI-assisted High Touch Support recovery system let attackers trigger password resets on 20,225 accounts, including 30 Maine residents. The incident was discovered on May 31 and tied in the filing to an April 17 attack; Meta said users without two-factor authentication were most exposed and that the bug could expose contact details, dates of birth, posts, direct messages, and linked services. Meta disabled the support tool, invalidated reset links, and forced impacted accounts through a security checkpoint.
Why it matters
It shows how account-recovery automation can become a large-scale account-takeover path.
Sources & driving stories
BLEEPINGCOMPUTER · Sergiu Gatlan
BleepingComputer coverageHACKREAD
Hackread coverageOxford discloses CareerConnect breach via GTI
Oxford University said its CareerConnect career-services platform was compromised on May 28 after third-party provider Group GTI notified it of the breach. The incident exposed first and last names, email addresses, and encrypted passwords for users who signed in locally rather than via SSO; Oxford said there is no evidence university systems, course data, uploaded files, appointments, or financial information were involved. GTI invalidated locally set passwords and the university warned users about phishing and scam emails.
Why it matters
A third-party breach can still expose students, alumni, and employers to credential-phishing campaigns.
Sources & driving stories
BLEEPINGCOMPUTER · Sergiu Gatlan
BleepingComputer coverageWorth noting
WORTH NOTING
Meta roadmap teases facial recognition wearables
The leak reportedly points to always-on biometric identification in future glasses, a sensitive privacy and consent issue if it materializes.
WORTH NOTING
Meta privacy settlement payouts resume
A second payout round from Meta's $725 million user-privacy settlement starts June 9, showing the long tail of the case.
WORTH NOTING
UK lawmakers question Palantir access
The NHS platform scrutiny centers on what patient data Palantir can see and what legal authority governs it.
Still unclear
OPEN QUESTION
Will Meta find similar recovery flaws?
Meta said it is reviewing similar recovery flows across its platforms, so the scope could extend beyond Instagram.
OPEN QUESTION
What patient data can Palantir access?
That answer determines whether the NHS platform is limited to pseudonymized operations or enables broader secondary use.
