Facebook's platform used to foment violence in Myanmar
Facebook commissioned an independent human rights impact assessment that concluded the company was not doing enough to prevent its platform from being used to foment division and incite offline violence in Myanmar. The assessment, conducted by BSR, found that Facebook's content moderation and AI systems failed to adequately detect and remove hate speech and misinformation, contributing to real-world harm. Facebook acknowledged the findings and implemented corrective measures, including hiring more local language reviewers and improving AI detection.
- Company involved
- Facebook
- AI system involved
- Facebook platform
10 source articles · read the reporting →
Meta AI privacy flaw exposed users' private chats, fixed after hacker report
A security researcher discovered a vulnerability in Meta's AI chatbot that could have allowed unauthorized access to users' private prompts and responses. The flaw, caused by guessable IDs and lack of ownership verification, was reported to Meta on 26 December 2024. Meta fixed the issue on 24 January 2025 and awarded the researcher a $10,000 bug bounty. The company stated that no evidence of exploitation was found.
- Company involved
- Meta
- AI system involved
- Meta AI
2 source articles · read the reporting →
Microsoft Copilot Exposes Private GitHub Repositories via Bing Cache
In August 2024, Lasso Security researchers discovered that Microsoft Copilot could access and expose data from private GitHub repositories that had been briefly public, due to Bing's caching mechanism. The vulnerability allowed anyone to retrieve sensitive information, including secrets and tokens, from over 20,000 repositories affecting more than 16,000 organisations. Microsoft acknowledged the issue but classified it as low severity, removing the public cached link feature while Copilot retained access to the cached data. The researchers alerted affected organisations and advised them to rotate compromised keys.
- Company involved
- Microsoft
- AI system involved
- Microsoft Copilot
2 source articles · read the reporting →
McDonald’s AI Hiring Platform Exposes 64 Million Applicants’ Data Due to Default Password
In late June 2025, security researchers discovered that McDonald’s AI-powered hiring platform, McHire, had a critical security flaw. A default admin password of '123456' allowed access to a live dashboard containing sensitive data of nearly 64 million job applicants. The researchers also found an insecure direct object reference vulnerability that could expose full applicant profiles and chat logs. McDonald’s and the platform’s vendor, Paradox.ai, quickly fixed the issues and stated that only five records were viewed by the researchers, with no public data leak.
- Company involved
- McDonald's
- AI system involved
- McHire
2 source articles · read the reporting →
341 Malicious ClawHub Skills Found Stealing OpenClaw User Data
Security researchers discovered 341 malicious skills on ClawHub, a marketplace for the OpenClaw AI assistant. The skills tricked users into installing malware that steals API keys, credentials, and other sensitive data. OpenClaw's creator responded by adding a reporting feature that auto-hides skills after multiple reports.
- Company involved
- OpenClaw
- AI system involved
- OpenClaw
4 source articles · read the reporting →
KPMG drops AI report after false case studies exposed
KPMG removed a global report on AI after multiple case studies were found to be inaccurate and apparently generated from AI hallucinations. The report falsely claimed that UBS, NHS Greater Manchester, Swiss Federal Railways and Transport for London used AI agents in various ways. The companies denied the claims, and KPMG took the report down while reviewing its production.
- Company involved
- KPMG
3 source articles · read the reporting →
Cense exposed 2.5 million records of auto accident victims online
On July 7, 2020, a security researcher discovered 2.5 million records containing personal and medical data of auto accident victims exposed online. The records, belonging to New York-based AI company Cense, included names, insurance policy numbers, claim numbers, and medical diagnosis notes. The data was labeled as staging data, possibly intended for temporary storage before being loaded into an AI system. After the researcher sent a responsible disclosure notice, Cense restricted public access to the database.
- Company involved
- Cense
- AI system involved
- Cense
5 source articles · read the reporting →
SEC warns public of deep fake investment scams featuring Lance Gokongwei
The Securities and Exchange Commission (SEC) warned the public that scammers are using deep fake videos and audio of Lance Gokongwei to endorse fraudulent investment schemes. The manipulated media circulate on social media, deceiving people into investing in a platform registered in Cyprus. Victims are asked to provide credit card details and OTPs, then lose contact when attempting to withdraw funds. The SEC advises the public to verify investment offers with the agency.
2 source articles · read the reporting →
UK councils use Covid OneView AI to harvest personal data for risk scoring
UK local authorities are using a system called Covid OneView, developed by data analytics firm Xantura, to harvest millions of personal details from council records. The system uses predictive analytics and AI to assign risk scores to households and individuals, aiming to identify those vulnerable to Covid or likely to break lockdown rules. Privacy campaigners and MPs have criticised the lack of transparency and the extent of data collection, which includes sensitive information such as debt levels, living arrangements, and even notes on unfaithful sex. Xantura and Barking and Dagenham Council have defended the system as compliant with data protection rules and focused on providing support.
- Company involved
- UK local authorities
- AI system involved
- Covid OneView
6 source articles · read the reporting →
Finnish recruitment company Digital Minds used AI to analyze job applicants' messages, prompting data protection investigation
Digital Minds, a Finnish recruitment company founded by psychologists, used IBM Watson AI to analyze job applicants' social media and email messages for personality assessments. The company obtained written consent but the Finnish Data Protection Ombudsman launched an investigation, suspecting violations of data protection laws and the secrecy of correspondence. The service was used on fewer than ten applicants and has been paused pending the investigation.
- Company involved
- Digital Minds
- AI system involved
- IBM Watson
9 source articles · read the reporting →
New York City's McKinsey-led jail violence program manipulated data, violence increased
New York City paid McKinsey & Company $27.5 million to reduce violence at Rikers Island jail complex. McKinsey designed a predictive algorithm called the Housing Unit Balancer and Restart housing units, but jail officials and McKinsey consultants stacked the units with compliant inmates to artificially lower violence numbers. Violence actually increased by nearly 50% during the project. The city eventually decided to close Rikers.
- Company involved
- New York City Department of Correction
- AI system involved
- Housing Unit Balancer (HUB)
10 source articles · read the reporting →
CanLII sues Caseway AI for scraping legal database
The Canadian Legal Information Institute (CanLII) has filed a lawsuit in British Columbia Supreme Court against Caseway AI, alleging that the company's AI chatbot scraped approximately 3.5 million records from CanLII's database in bulk, violating its terms of service and copyright. CanLII claims it adds value to public court records through hyperlinks and corrections, which it says constitute protected copyrighted work. Caseway AI argues the information is public and accessible elsewhere, and that it did not use CanLII's enhancements. The lawsuit was settled in March 2026, with terms undisclosed.
- Company involved
- Canadian Legal Information Institute (CanLII)
- AI system involved
- Caseway
5 source articles · read the reporting →
Meta's content moderation errors during May 2021 Israel-Palestine escalation
During the May 2021 escalation of violence in Israel and Palestine, Meta's automated content moderation systems temporarily restricted access to the al-Aqsa hashtag page and under-enforced rules against incitement to violence against Israelis and Jews. An independent due diligence report commissioned by Meta found that these systems had an unintentional impact on Palestinian and Arab communities' freedom of expression. Meta has committed to implementing several recommendations, including improving machine learning classifiers and keyword review processes.
- Company involved
- Meta
- AI system involved
- Facebook and Instagram content moderation systems
10 source articles · read the reporting →
Elon Musk asks X users to upload medical data to train Grok chatbot
Elon Musk has told X users to upload medical images to the platform so that the AI chatbot Grok can learn to interpret them. He claimed Grok can give medical diagnoses, sometimes better than doctors, but experts have raised concerns about accuracy and privacy. The article reports cases where Grok misread a tuberculosis case and a mammogram. xAI, which owns X, responded to Fortune: 'Legacy Media Lies.'
- Company involved
- X
- AI system involved
- Grok
6 source articles · read the reporting →
California regulator accuses Maxpread Technologies of using AI-generated fake CEO to scam investors
Maxpread Technologies allegedly used an AI-generated avatar to pose as its CEO in a YouTube video to deceive investors. The California DFPI issued cease and desist letters to Maxpread and four other companies for offering unqualified securities and making false promises. The regulator claims the companies promised high daily returns using AI trading, but these claims were false. Maxpread did not respond to requests for comment.
- Company involved
- Maxpread Technologies
8 source articles · read the reporting →
DeepSeek exposed user data via open ClickHouse database
Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
Cigna StressWaves Test found unreliable and invalid in independent study
A study published in Scientific Reports evaluated the Cigna StressWaves Test (CSWT), an AI tool that claims to assess psychological stress from speech. The study found that the CSWT had poor test-retest reliability and poor validity compared to the Perceived Stress Scale. The authors warned that widespread availability of the tool could lead to misleading results and negative consequences for users making healthcare decisions. Cigna has not publicly responded to the findings.
- Company involved
- Cigna
- AI system involved
- Cigna StressWaves Test
4 source articles · read the reporting →
Meta tracks employee keystrokes on Google, LinkedIn, Wikipedia for AI training
Meta is using an internal tool, Model Capability Initiative (MCI), to capture employees' keystrokes, mouse movements and screen contents on work computers, including on sites such as Google, LinkedIn, Wikipedia and Slack, to train AI agents. Meta confirmed the project and said safeguards protect sensitive content and that the data is not used for other purposes. Employees raised concerns in internal messages that the tool could expose passwords, product details and personal information. A Meta memo said staff can avoid capture by not doing personal work on work computers.
- Company involved
- Meta
- AI system involved
- Model Capability Initiative (MCI)
5 source articles · read the reporting →
AI image generators produce misleading election images, study finds
A study by the Center for Countering Digital Hate found that leading AI image generators, including Midjourney, DreamStudio, ChatGPT Plus, and Microsoft Image Creator, could be manipulated to create misleading election-related images. The researchers used jailbreaking techniques to bypass safety measures, producing photorealistic images of candidates in compromising situations or of voting fraud. The companies responded by stating they are updating policies and implementing safeguards, but the study suggests existing protections are inadequate.
- Company involved
- Midjourney, Stability AI, OpenAI, Microsoft
- AI system involved
- Midjourney, DreamStudio, ChatGPT Plus, Microsoft Image Creator
8 source articles · read the reporting →
Slack trains AI features on user messages and files by default
Slack uses user messages, files, and data to train its machine learning features such as channel recommendations and emoji suggestions. Users are opted in by default and cannot individually opt out; only workspace administrators can request exclusion via email. A user publicly criticized the practice, and Slack acknowledged the policy but did not change it.
- Company involved
- Slack
10 source articles · read the reporting →
X's Grok exposed hundreds of thousands of user chats in Google
Hundreds of thousands of conversations with Elon Musk's AI chatbot Grok were indexed by Google Search and made publicly accessible without users' knowledge. The exposure occurred when users pressed a share button that created unique links, but those links were also searchable online. The BBC reported the incident after Forbes initially identified more than 370,000 exposed chats. Experts described the leak as a privacy disaster, and X has not publicly responded.
- Company involved
- X
- AI system involved
- Grok
5 source articles · read the reporting →
OpenDream AI art site allowed users to generate child sexual abuse material
OpenDream, an AI image generation platform, allowed users to generate and publicly display child sexual abuse material (CSAM) and non-consensual deepfakes from at least December 2023 until July 2024. The platform, operated by CBM Media Pte Ltd in Singapore, offered paid plans with NSFW prompts and models. Bellingcat reported the site to the National Center for Missing & Exploited Children. After Bellingcat's inquiry, the CSAM was removed from the site and search engines, and Google terminated OpenDream's AdSense account.
- Company involved
- CBM Media Pte Ltd
- AI system involved
- OpenDream
3 source articles · read the reporting →
Dutch probe into chatbots' voting advice raises EU AI Act risk for OpenAI, xAI, Mistral
A Dutch privacy probe into election advice has appeared to expose early violations of the EU AI Act's rules for general-purpose AI models by OpenAI, xAI and Mistral, according to MLex. The companies' chatbots provided distorted voting advice to users. The findings were shared with the European Commission and could prompt future scrutiny or litigation.
- Company involved
- OpenAI, xAI and Mistral
6 source articles · read the reporting →
News/Media Alliance study finds unauthorised use of publisher content to train AI
The News/Media Alliance alleges that generative AI developers have copied and used publishers' content without authorisation to train large language models. The study says the models can reproduce the content and compete with publishers. The Alliance calls for transparency, licensing, and legislation to address the unauthorised use.
10 source articles · read the reporting →