Meta moved quickly over the weekend to shut down a vulnerability in its AI-powered customer support system on Instagram. The flaw let determined attackers request password reset links for targeted accounts and receive them directly, sidestepping two-factor authentication entirely. No backend systems were breached. Yet the incident exposes how conversational AI, when granted even limited authority over identity actions, can become an unwitting accomplice in account takeovers. The problem surfaced publicly in recent days as security researchers and underground forums noted unusual activity around high-value Instagram handles. Short, memorable usernames and verified accounts suddenly appeared for sale on Telegram channels. Some listings commanded prices exceeding $1 million. One prominent example involved the handle associated with the Obama White House, according to multiple reports circulating on X and cybersecurity sites. Attackers didn’t need the victim’s password or 2FA codes.…