Key developments
Instagram recovery bug exposed 20,225 accounts
Meta disclosed a flaw in Instagram's AI-assisted High Touch Support recovery flow that could send password reset links to an email address not tied to the target account. The company said the issue affected 20,225 people, including 30 Maine residents, and created takeover risk for accounts without two-factor authentication. Meta said it discovered the bug on May 31, disabled the tool the same day, and invalidated all reset links generated through the vulnerable path.
Why it matters
A recovery-flow validation failure turned a support feature into a potential account-takeover vector for thousands of users.
Sources & driving stories
HACKREAD
Hackread coverageSynnovis breach notification widens to Essex trust
Mid and South Essex NHS Foundation Trust said it will contact patients after being told their data was among the material stolen in Synnovis's 2024 Qilin ransomware attack. Computer Weekly says about 2,380 records are involved, and the exposed test data relate to tests completed before June 3, 2024. The trust said some records are not directly linked to patients, so exact counts are still being finalized, underscoring how the breach's downstream notification phase is still expanding nearly 18 months later.
Why it matters
The incident shows how ransomware notification obligations can keep widening long after the original intrusion.
Sources & driving stories
COMPUTER WEEKLY
Computer Weekly coverageWhatsApp seeks contempt over NSO phishing
WhatsApp says NSO Group used spearphishing and social engineering attempts against its users despite an October court order barring NSO from using WhatsApp as an attack vector. The Meta-owned service said it detected the activity after user reports, removed NSO-created test accounts and groups, and filed a contempt motion in federal court. The latest lures pushed users toward malicious links on external websites, echoing earlier NSO-linked phishing campaigns.
Why it matters
If upheld, the contempt action could tighten pressure on a spyware vendor accused of violating an existing injunction.
Sources & driving stories
THE RECORD · Suzanne Smalley
The Record coverageWorth noting
WORTH NOTING
FTC orders Illuminate security overhaul
The order follows a breach affecting more than 10 million current and former students and adds new limits on retention, disclosure, and breach reporting.
WORTH NOTING
PSNI breach leads to conviction
It is a rare example of leaked police data becoming part of a terrorism case, showing how privacy breaches can have downstream criminal consequences.
Still unclear
OPEN QUESTION
How many more NHS trusts will notify patients?
Synnovis's forensic review is still cascading through the NHS, and the final number of affected records and organizations remains unresolved.
OPEN QUESTION
Did any Instagram accounts get accessed?
Meta says the bug could enable takeover, but it has not said whether attackers actually viewed data or logged in before the fix.
