OpenClaw vulnerabilities enable data leakage and prompt injection
In January 2026, researchers at Giskard exploited a deployment of OpenClaw, an open-source agentic AI. They found that architectural weaknesses in the Control UI and session management allowed prompt injection and unauthorized tool use, leading to potential data leakage across user sessions. The article outlines hardening steps to prevent such vulnerabilities.
- AI system involved
- OpenClaw
6 source articles · read the reporting →
Miami Police Used Clearview AI to Identify Protester
NBC 6 Investigators revealed that Miami Police used the facial recognition program Clearview AI to identify Oriana Albornoz, a 25-year-old woman, as the person accused of throwing rocks at officers during a protest on May 30, 2020. She was arrested a month later and charged with battery on a police officer; her attorney said he was unaware police had used the technology, as it was not disclosed in the arrest report. The police department acknowledged using Clearview AI to identify violent protest suspects after the fact, but stated they do not surveil peaceful protesters. The case is ongoing, with Albornoz pleading not guilty.
- Company involved
- Miami Police Department
- AI system involved
- Clearview AI
4 source articles · read the reporting →
Ring's AI pet-search feature draws privacy backlash after Super Bowl ad
Ring, an Amazon company, promoted its Search Party feature in a Super Bowl advertisement, saying its AI helps reunite dog owners with missing pets. Critics said the feature, which is enabled by default, turns Ring doorbells into a mass surveillance network and could easily be adapted to track people. Ring said it had reunited 99 dogs in the US in 90 days and that customers keep full control of their data.
- Company involved
- Ring
- AI system involved
- Search Party
5 source articles · read the reporting →
Mexican government agencies hacked using Anthropic's Claude AI
Anthropic's Claude large language model was weaponized by attackers to compromise numerous Mexican government agencies over a month-long campaign starting December 2025. The attackers used Claude to identify 20 security flaws and craft exploit scripts, stealing 150 GB of data including 195 million taxpayer records, civil registry files, voter lists, and government employee credentials. Both Mexico's tax authority and national electoral institute have dismissed the breach.
- Company involved
- Anthropic
- AI system involved
- Claude
5 source articles · read the reporting →
Pankaj says his AI kitchen monitor caught the cook taking fruit and she was fired
Pankaj posted on X that he had set up an AI-powered kitchen monitor, using Claude Haiku 4.5 as its vision model, to watch his cook while she worked. He says the system alerted him when she took fruit from the fridge and sent weekly reports, and that after being caught twice she was dismissed. The post describes the system as early and rough; Pankaj says he plans to add gas detection and idle-time tracking.
- Company involved
- Pankaj
- AI system involved
- AI roommate
5 source articles · read the reporting →
AI chatbots recommended unlicensed casinos to UK users
An investigation by the Guardian and Investigate Europe found that five major AI chatbots—ChatGPT, Gemini, Grok, Microsoft Copilot, and Meta AI—recommended unlicensed online casinos to UK users. Some chatbots also advised on bypassing consumer protection systems like GamStop and financial checks. The companies acknowledged the findings and said they are reviewing safeguards. Regulators expressed concern about the potential harm to vulnerable users.
- Company involved
- Multiple technology companies (Microsoft, Google, Meta, OpenAI, X)
- AI system involved
- Copilot, Gemini, Meta AI, ChatGPT, Grok
5 source articles · read the reporting →
Police Investigator Accused of Making Over 4,000 Illegal Flock Camera Searches - Futurism
The system allowed unauthorized tracking of individuals' vehicles through license plate recognition, affecting five subjects including an ex-girlfriend who was searched 3,000 times.
- Company involved
- Albany County Sheriff's Office
- AI system involved
- Flock Safety ALPR
1 source article · read the reporting →
Former Police Officer Sentenced to 5 Years After Misusing Flock Cameras To Stalk Ex-Girlfriend - Texas Scorecard
Former officer used Flock cameras to surveil and stalk his ex-girlfriend, her family members, and other romantic interests.
- Company involved
- Flock Safety
1 source article · read the reporting →
Hackers Extract Encryption Keys from Flock Surveillance Cameras, Revealing Person Detection Alongside Vehicle Tracking - finance.biggo.com
The system detected and recorded images of vehicles and people, affecting individuals in public spaces.
- Company involved
- Flock Safety
- AI system involved
- Flock Safety ALPR cameras
1 source article · read the reporting →
Flock seeks to have security researchers' map of Flock cameras taken down — unauthenticated flaw exposed 335,701 camera locations nationwide…
The system captured license plate data and vehicle locations of individuals passing the cameras.
- Company involved
- Flock Safety
- AI system involved
- Flock Safety cameras
1 source article · read the reporting →
New Meta smart glasses class action gives employers a reason to write the policy they've been puttin - hcamag.com
The smart glasses recorded bystanders without their consent and sent the footage to Meta for AI training.
- Company involved
- Meta Platforms
- AI system involved
- Meta AI-enabled Ray-Ban and Oakley smart glasses
1 source article · read the reporting →
Spanish data regulator orders Worldcoin to stop processing biometric data in Spain
The Spanish Data Protection Agency (AEPD) has ordered a precautionary measure against Tools for Humanity Corporation, the company behind Worldcoin, to cease collection and processing of personal data in Spain. The AEPD received complaints alleging insufficient information, collection of data from minors, and inability to withdraw consent. The regulator acted under GDPR Article 66.1 to prevent potentially irreparable harm to individuals' data protection rights.
- Company involved
- Tools for Humanity Corporation
- AI system involved
- Worldcoin
8 source articles · read the reporting →
Evolv backtracks on claimed UK government testing of AI weapons scanner
Evolv Technology, maker of AI-powered weapons scanners, backtracked on claims that its system had been tested by the UK government's National Protective Security Authority. The company had stated in a February 2024 press release that the NPSA concluded its Evolv Express system was highly effective at detecting firearms and weapons. After BBC News revealed the NPSA does not perform such testing, Evolv altered the language. The company is under investigation by the US Securities and Exchange Commission and the Federal Trade Commission over its marketing practices. Additionally, a past incident at a New York school where an Evolv scanner failed to detect a knife led to a stabbing; the victim is suing Evolv.
- Company involved
- Evolv Technology
- AI system involved
- Evolv Express
3 source articles · read the reporting →
Portuguese regulator suspends Worldcoin's biometric data collection
Portugal's data protection authority, CNPD, has ordered Worldcoin Foundation to suspend collection of iris, eye and facial biometric data in Portugal for 90 days. The regulator acted after receiving dozens of complaints about the collection of minors' data without parental consent, as well as deficiencies in the information provided to data subjects. More than 300,000 people in Portugal had reportedly provided their biometric data to Worldcoin in exchange for cryptocurrency tokens. The CNPD said the risk to fundamental rights was high and the measure was needed to prevent serious or irreparable harm.
- Company involved
- Worldcoin Foundation
- AI system involved
- Orb
5 source articles · read the reporting →
Pearl Gardner v. Nationstar Mortgage LLC (D. Arizona): AI-hallucinated content in court filing, Bar Referral
Pro Se Litigant | D. Arizona | State(s): USA. AI tool: Clearpoint. Problem: Fabricated: Case Law. Consequence: Bar Referral.
1 source article · read the reporting →
Cybercheck AI tool challenged in Akron homicide cases
Law enforcement in Akron, Ohio, used the AI tool Cybercheck to place two defendants at a murder scene. Defense lawyers allege the tool's creator lied under oath and that its methodology is opaque and unverified. Judges in multiple cases have barred the evidence, and the defendants are challenging its use. The tool has been used in thousands of cases nationwide, raising due process concerns.
- Company involved
- Akron Police Department
- AI system involved
- Cybercheck
3 source articles · read the reporting →
Boulder police chief faces class action over Flock cameras' warrantless surveillance - Courthouse News
The system captured and stored license plate data and vehicle movements of Boulder residents and commuters, making it searchable by law enforcement without a warrant.
- Company involved
- Boulder Police Department
- AI system involved
- Flock Safety
1 source article · read the reporting →
Former Emerson officer accused of misusing Flock camera system - wrganews.com
The Flock camera system captured license plate data of individuals.
- Company involved
- Acworth Police Department
- AI system involved
- Flock Safety System
1 source article · read the reporting →
FTC charges Ring with illegal surveillance and security failures
The Federal Trade Commission charged Ring, a home security camera company, with compromising customer privacy by allowing employees to access private videos and failing to prevent hackers from taking control of cameras. Hackers accessed approximately 55,000 U.S. customers' accounts, harassing individuals including children and the elderly. The proposed order requires Ring to pay $5.8 million in refunds and implement security measures.
- Company involved
- Ring LLC
- AI system involved
- Ring cameras
10 source articles · read the reporting →
Ningbo fines property developers for using facial recognition without consent
In Ningbo, China, property developers were fined for using facial recognition technology to identify customers without their consent. The enforcement followed China's annual Consumer Protection Gala that highlighted misuse of facial recognition. The fines were imposed by the local government and the developers were accused of violating privacy regulations.
- Company involved
- Multiple property developers in Ningbo
- AI system involved
- Facial recognition technology
6 source articles · read the reporting →
Zhihu denies using behaviour perception system to monitor employees
Zhihu, a Chinese Q&A platform, was accused of using a behaviour perception system to monitor employees' visits to job-seeking websites and resume submissions. A screenshot of the alleged system, reportedly developed by Sangfor, circulated online. Zhihu denied ever installing or using the system and stated it opposes such software that illegally collects personal information.
- Company involved
- Zhihu
- AI system involved
- Behaviour perception system
4 source articles · read the reporting →
Engineer.ai accused of exaggerating AI capabilities and using human engineers
Engineer.ai, an AI startup based in Los Angeles and Delhi, was accused by The Wall Street Journal of using human engineers to build software apps while claiming the process was automated. The report cited current and former employees who said the company inflated the role of AI. Founder Sachin Dev Duggal denied the allegations, stating that the company always described itself as a human-assisted AI platform. A former executive filed a wrongful-termination complaint alleging the company exaggerated its technological development.
- Company involved
- Engineer.ai
6 source articles · read the reporting →
Tenant screening software denies housing to disabled Latino man in Connecticut
In 2016, Carmen Arroyo requested to move her disabled son Mikhail into a larger apartment in the same complex. The landlord, WinnResidential, used CoreLogic's CrimSafe tenant screening software, which flagged a dropped retail theft charge against Mikhail as disqualifying. The landlord rejected the application without explanation. Arroyo sued CoreLogic and WinnResidential under the Fair Credit Reporting Act and the Fair Housing Act, alleging that the software disproportionately excludes people of colour. The case was scheduled for trial in August 2021.
- Company involved
- WinnResidential
- AI system involved
- CrimSafe
10 source articles · read the reporting →
Cruzcampo deepfake ad of Lola Flores goes viral
Cruzcampo launched an advertising campaign using a deepfake video of the late singer Lola Flores, created with artificial intelligence. The video went viral shortly after release. The company explained the technical process and involved Flores' daughters in the project.
- Company involved
- Cruzcampo
10 source articles · read the reporting →