When the Interface Is the Vulnerability
What the Meta AI incident institutionalizes is a new threat category: the conversational attack vector. Security infrastructure built around code injection, credential stuffing, and network intrusion has no established playbook for an attacker who simply chats a chatbot into sending reset links to the wrong address. As human-in-the-loop AI deployment for operational contexts becomes standard practice, the absence of a human checkpoint on consequential AI actions — like initiating an account recovery — is the gap exploited here. Meta's two-month detection window is the benchmark every security team now has to beat, and most have not yet started measuring.