42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE
SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.
- AI system involved
- OpenClaw
5 source articles · read the reporting →
Stable Diffusion Accused of Stealing Artists' Styles Without Consent
Artists including Greg Rutkowski and Karla Ortiz allege that Stability AI's image generator Stable Diffusion was trained on their work without permission, enabling users to create images mimicking their distinctive styles. The artists express concern that this threatens their livelihoods and identities, as their names become prompts for generating similar art. A tool is being developed to help protect artists from such unauthorised use, but the situation remains unresolved.
- Company involved
- Stability AI
- AI system involved
- Stable Diffusion
10 source articles · read the reporting →
AI rapper Danny Bones used by Advance UK in byelection campaign
The Node Project created an AI-generated rapper named Danny Bones who produces white-nationalist music targeting Muslims. Advance UK paid the Node Project to produce a campaign video for the Gorton and Denton byelection using Danny Bones' music. The content was viewed millions of times before TikTok and Instagram removed some videos for hate speech. The Electoral Commission is investigating.
- Company involved
- Node Project
- AI system involved
- Danny Bones
3 source articles · read the reporting →
UK prison risk algorithm may embed racial bias, experts warn
The Ministry of Justice developed a digital tool to categorize prisoners, which experts and advocacy groups warn could automate and embed racism. The tool uses intelligence data that may reflect existing bias, potentially leading to disproportionate categorization of BAME prisoners. The MoJ claims no evidence of discrimination, but critics question the small trial sample and lack of transparency.
- Company involved
- Ministry of Justice
- AI system involved
- Digital prisoner categorisation tool
5 source articles · read the reporting →
Buenos Aires city government uses live facial recognition to track minors in criminal database
The Buenos Aires city government deployed a live facial recognition system in April 2019 that scans subway passengers and matches them against CONARC, a national database of alleged offenders. Human Rights Watch found that the database includes at least 166 children, some as young as one to three years old, and that the system has led to numerous false arrests. The system was implemented without public consultation, and there is no mechanism to correct mistakes. A civil rights organization filed a lawsuit, and the government is pushing a bill to legalize the technology.
- Company involved
- Buenos Aires city government
1 source article · read the reporting →
Ukrainian Hacker Pleads Guilty to Operating OnlyFake AI ID Scam Site
Yurii Nazarenko, a Ukrainian national, pleaded guilty to running OnlyFake, an AI-powered website that generated and sold over 10,000 counterfeit identification documents globally. The site allowed users to create realistic fake IDs, including driver's licenses and passports, to bypass identity verification at banks and cryptocurrency exchanges. Nazarenko faces up to 15 years in prison and agreed to forfeit $1.2 million. Sentencing is scheduled for June 2026.
- Company involved
- OnlyFake
- AI system involved
- OnlyFake
3 source articles · read the reporting →
Bahia Facial Recognition System Misidentifies Black Man as Wanted Criminal
Davi, a black administrative assistant, was tracked across 15 metro stations and approached by police after Bahia's facial recognition system falsely matched him to a wanted person. He was released after officers verified his identity. The system, supplied by Iecisa and Huawei, has a low accuracy rate and disproportionately affects black people. The government plans to expand it despite concerns over racial bias and errors.
- Company involved
- Secretaria de Segurança Pública da Bahia
2 source articles · read the reporting →
Greek Data Protection Authority fines Ministry of Migration and Asylum for AI surveillance systems
The Hellenic Data Protection Authority (HDPA) imposed an administrative fine of €175,000 on the Ministry of Migration and Asylum (MMA) for GDPR violations related to the 'Centaur' and 'Hyperion' programmes. These systems use AI behavioral analytics, CCTV, drones, and biometric data to monitor and control access to reception facilities for asylum seekers on Greek islands. The HDPA found that the MMA failed to conduct proper Data Protection Impact Assessments and did not cooperate with the authority. The MMA has been ordered to comply with GDPR within three months.
- Company involved
- Ministry of Migration and Asylum
- AI system involved
- Centaur and Hyperion programmes
10 source articles · read the reporting →
Manchester City to Trial Facial Recognition at Etihad Stadium
Manchester City are set to trial facial recognition software supplied by Blink Identity at the Etihad Stadium. The system would scan fans' faces to check whether they have bought tickets and allow entry, with the aim of reducing matchday queues. Fans would need to sign up using a picture of their face. The article notes concerns about the potential security of users, but the club and vendor say they are committed to protecting fans.
- Company involved
- Manchester City
1 source article · read the reporting →
Clearview AI facial recognition app scrapes billions of images and is used by police
Clearview AI, a secretive start-up, built a facial recognition app that matches photos to a database of more than three billion images scraped from social media and websites. More than 600 law enforcement agencies, including the FBI and Department of Homeland Security, have used the tool to identify suspects in crimes such as shoplifting, identity theft and murder. The company monitored officers who ran a reporter's photo through the app, and its founder acknowledged designing an augmented-reality prototype but said there were no plans to release it. Critics warned the tool could end anonymity and enable misuse.
- Company involved
- Clearview AI
- AI system involved
- Clearview AI facial recognition app
2 source articles · read the reporting →
IDF Used AI System Lavender to Target Tens of Thousands in Gaza
The Israeli military used an AI system called Lavender to identify suspected militants in Gaza, marking 37,000 Palestinians as targets for bombing with minimal human oversight. Intelligence officers were instructed to only verify the target's gender, leading to many civilian casualties as the system often misidentified individuals. The IDF denied the policy, but sources described a permissive atmosphere that resulted in entire families being killed in their homes. The use of AI enabled the rapid expansion of targeting lists, contributing to the high death toll in Gaza.
- Company involved
- Israel Defense Forces
- AI system involved
- Lavender
9 source articles · read the reporting →
PredictiveHire builds AI to predict job hopping from interviews
PredictiveHire, an AI hiring firm, developed a machine-learning model that analyses candidates' open-ended interview responses to predict their likelihood of 'job hopping'. The company used data from 45,899 applicants to build the 'flight risk' assessment, which it advertises as coming soon. Scholars warn that such tools can suppress wages by screening out workers who might seek better pay or conditions, continuing a historical trend of using personality tests to identify potential labour organisers.
- Company involved
- PredictiveHire
- AI system involved
- Phai
1 source article · read the reporting →
Jacksonville Sheriff's Office facial recognition leads to wrongful arrest of Florida man
Robert Dillon, a commercial crabber in Lee County, Florida, was arrested after the Jacksonville Sheriff's Office used facial recognition to match restaurant surveillance photos to him, leading to a warrant for luring or enticing a child. Dillon said he had never been to Jacksonville Beach and pointed to visible differences between himself and the suspect. His defence attorney argued the investigation relied too heavily on the AI match, and the state attorney’s office dropped the case after further investigation. Dillon is now seeking a civil attorney to pursue legal action over the wrongful arrest.
- Company involved
- Jacksonville Sheriff's Office
2 source articles · read the reporting →
Xuhui police expand facial recognition surveillance to profile 1.1 million residents
The Xuhui District branch of the Shanghai Municipal Bureau of Public Security is expanding its Intelligent Image Recognition System, adding 2,500 facial recognition cameras and increased computing capacity to build profiles of residents and flag deviations. The project, contracted to US-sanctioned FiberHome, is designed to match each face to files on more than 50 million people. Officials say the system will analyse behaviour patterns and trigger early warnings.
- Company involved
- Shanghai Municipal Bureau of Public Security, Xuhui District Branch
- AI system involved
- Intelligent Image Recognition System
3 source articles · read the reporting →
NYPD Facial Recognition Leads to Wrongful Arrest of Trevis Williams
In April 2025, Trevis Williams was arrested by the NYPD after a facial recognition program matched his mug shot to a suspect in a February flashing incident, despite an eight-inch height difference and alibi evidence. The victim identified him from the AI-suggested photo array. Mr. Williams spent over two days in jail before the case was dismissed in July. The incident highlights the risks of using facial recognition on low-quality surveillance images.
- Company involved
- New York Police Department
2 source articles · read the reporting →
West Midlands Police test NDAS system to assess crime risk
West Midlands Police are testing a system called the National Data Analytics Solution (NDAS) that analyses police data to assess the risk of individuals committing a crime or becoming a victim. The Home Office has funded the project with millions of pounds, intending to roll it out across England and Wales. Critics warn that the system could reinforce bias against minorities and undermine the presumption of innocence. The police say the technology is designed to support, not replace, officer decision-making and that it is still in early testing.
- Company involved
- West Midlands Police
- AI system involved
- National Data Analytics Solution
1 source article · read the reporting →
Dahua Exposed for Uyghur Tracking Software in Surveillance Systems
Dahua Technology's publicly available SDK was found to contain code for detecting Uyghur ethnicity, enabling Chinese police to covertly track the persecuted minority. The revelation led to widespread criticism, and Dahua removed the SDK after being contacted by IPVM but did not comment. The company had previously been sanctioned by the US for complicity in human rights abuses against Uyghurs, and its software is part of a massive surveillance apparatus in Xinjiang.
- Company involved
- Dahua Technology
- AI system involved
- Dahua SDK
1 source article · read the reporting →
Las Vegas police used unsuitable facial recognition images in nearly half of searches
The Las Vegas Metropolitan Police Department (LVMPD) used 'non-suitable' probe images in 451 of 924 facial recognition searches in 2019, greatly increasing the risk of false identifications. The system, supplied by Vigilant Solutions, returned likely matches in only 18% of those searches, yet led to arrests in at least 73 cases. Critics and researchers warn this practice heightens the chance of wrongful arrests, and one defence attorney said he was never informed facial recognition was used to identify his client.
- Company involved
- Las Vegas Metropolitan Police Department
- AI system involved
- Vigilant Solutions facial recognition system
1 source article · read the reporting →
Arizona Unemployment Applicants Required to Submit Facial Recognition
People applying for unemployment benefits in Arizona must verify their identity via facial recognition software provided by ID.me. If the system fails to match a selfie to a photo ID, applicants can be denied benefits unless they successfully complete a video chat with a referee. A class-action lawsuit filed in June 2021 alleges that the practice violates due process rights and discriminates against people of colour.
- Company involved
- Arizona Department of Economic Security
- AI system involved
- ID.me
1 source article · read the reporting →
NYPD Used Facial Recognition to Target Black Lives Matter Activist Derrick Ingram
The NYPD used facial recognition technology to identify Derrick Ingram, a 28-year-old Black Lives Matter activist, leading to a raid on his Hell's Kitchen apartment by over 50 officers on 7 August 2020. The NYPD's Facial Identification Section generated a lead from a photo taken from Ingram's Instagram page, despite the department's policy of using only surveillance video or arrest photos. Ingram's attorney alleges the five-hour siege was an intimidation campaign that interfered with his constitutional rights. The NYPD acknowledged using facial recognition as a limited investigative tool.
- Company involved
- NYPD
- AI system involved
- Facial Identification Section
3 source articles · read the reporting →
Steak 'n Shake sued over facial recognition kiosks under BIPA
A class action lawsuit alleges that Steak 'n Shake illegally collects facial biometrics from customers using PopID-powered self-ordering kiosks without proper consent. Plaintiff Michael Massel claims the restaurant chain failed to provide notice and obtain written consent as required by Illinois' Biometric Information Privacy Act (BIPA). The suit seeks damages of up to $5,000 per violation for anyone whose biometric data was collected in Illinois in the past five years.
- Company involved
- Steak 'n Shake
- AI system involved
- PopID biometric kiosks
6 source articles · read the reporting →
ICE Agents Stored Photos and License Plates of Protest Observers in Palantir-Built Database, Court Filing Reveals - Latin Times
A court filing alleges ICE agents stored photos and license plates of protest observers in a Palantir-built database, labeled some of them as threats, and ran facial recognition searches on them.
- Company involved
- U.S. Immigration and Customs Enforcement (ICE)
- AI system involved
- ICM (Investigative Case Management system)
1 source article · read the reporting →
OpenClaw vulnerabilities enable data leakage and prompt injection
In January 2026, researchers at Giskard exploited a deployment of OpenClaw, an open-source agentic AI. They found that architectural weaknesses in the Control UI and session management allowed prompt injection and unauthorized tool use, leading to potential data leakage across user sessions. The article outlines hardening steps to prevent such vulnerabilities.
- AI system involved
- OpenClaw
6 source articles · read the reporting →
Thailand halts iris-scan crypto scheme and deletes 1.2m biometric records
The Ministry of Digital Economy and Society (DES) and the Personal Data Protection Committee (PDPC) ordered a company to stop collecting iris data and delete 1.2 million citizen records. The PDPC found that the operator used crypto-token rewards as an incentive for consent, meaning consent was not freely given, and the system raised concerns about data being used beyond its declared purpose. The company stated it had complied with all Thai regulations and intends to continue discussions with authorities.
- Company involved
- The company behind the iris-scan system (not named)
- AI system involved
- Iris-scan system
4 source articles · read the reporting →