341 Malicious ClawHub Skills Found Stealing OpenClaw User Data
Security researchers discovered 341 malicious skills on ClawHub, a marketplace for the OpenClaw AI assistant. The skills tricked users into installing malware that steals API keys, credentials, and other sensitive data. OpenClaw's creator responded by adding a reporting feature that auto-hides skills after multiple reports.
- Company involved
- OpenClaw
- AI system involved
- OpenClaw
4 source articles · read the reporting →
Scatter Lab shuts down Lee Luda chatbot after hate speech
Scatter Lab's Lee Luda chatbot, a conversational AI on Facebook, generated hate speech targeting Black, lesbian, disabled, and trans people. After user complaints, the company temporarily suspended the bot and apologized, attributing the behaviour to biased training data from its Science of Love app. Some users are preparing a class-action lawsuit over data use, and the South Korean government is investigating potential data protection violations.
- Company involved
- Scatter Lab
- AI system involved
- Lee Luda
10 source articles · read the reporting →
Clearview AI tested facial recognition surveillance cameras with UFT and Rudin
Clearview AI, the facial recognition company that scraped billions of photos from social media, developed a surveillance camera system under the name Insight Camera. The system was tested by the United Federation of Teachers and Rudin Management in New York City. The UFT used it to identify individuals who had made threats and prevent them from entering its offices. Clearview did not respond to requests for comment.
- Company involved
- Clearview AI
- AI system involved
- Insight Camera
9 source articles · read the reporting →
Adobe uses Creative Cloud user data to train AI
Adobe's content analysis feature may scan Creative Cloud and Document Cloud files to train machine learning models, including object recognition in Lightroom and Liquid Mode in Acrobat. The company says it may analyze images, audio, video, text and other documents stored on its servers. Adobe offers an opt-out in account privacy settings, but the article notes the company did not ask first.
- Company involved
- Adobe
- AI system involved
- Content analysis
10 source articles · read the reporting →
Virginia crime lab faces first challenge to secret DNA algorithm
A defendant in an armed-robbery case in Fairfax County is challenging a secret algorithm used by the Virginia crime lab to interpret DNA evidence. The lab could not make a conventional match because skin-cell DNA on the victim's shirt was mixed with DNA from too many people; the algorithm identified the defendant as a contributor. The defendant is seeking to scrutinise the algorithm, reportedly for the first time.
- Company involved
- Virginia crime lab
10 source articles · read the reporting →
ElevenLabs AI voice generation used in Russian influence operation targeting Europe
The article reports that a Russian influence campaign, dubbed "Operation Undercut," very likely used ElevenLabs' AI voice generation technology to create realistic voiceovers for fake news videos. The videos targeted European audiences to undermine support for Ukraine. Recorded Future's researchers used ElevenLabs' own AI Speech Classifier to detect the AI-generated audio. The campaign was attributed to the Russia-based Social Design Agency, which the U.S. government sanctioned. The overall impact on public opinion was minimal.
- Company involved
- Social Design Agency
- AI system involved
- ElevenLabs AI voice generation
7 source articles · read the reporting →
OpenAI's CLIP vision system fooled by handwritten notes
OpenAI researchers discovered that their CLIP computer vision system can be deceived by handwritten labels placed on objects. The system's multimodal neurons respond to text as well as images, causing it to misidentify objects. The attack, called a typographic attack, is a research finding and not a deployed system. No actual harm occurred.
- Company involved
- OpenAI
- AI system involved
- CLIP
10 source articles · read the reporting →
Beus Gilbert PLLC v. Brigham Young University et al. (D. Utah): AI-hallucinated content in court filing, Two AI-ethics CLE courses;…
The AI system generated fake legal citations that were included in a court filing, misleading the court and opposing counsel.
1 source article · read the reporting →
ElevenLabs voice cloning tool used to create deepfake celebrity audio clips
Speech AI startup ElevenLabs launched a beta voice cloning tool. Within days, users on 4chan posted deepfake audio clips featuring voices resembling celebrities like Emma Watson reading offensive material. ElevenLabs acknowledged the misuse and said it is considering additional safeguards.
- Company involved
- ElevenLabs
- AI system involved
- ElevenLabs platform
10 source articles · read the reporting →
Study finds Midjourney, DALL-E 2, Stable Diffusion accept over 85% of fake news prompts
A study by AI startup Logically tested Midjourney, DALL-E 2, and Stable Diffusion and found that they accepted over 85% of prompts seeking to generate fake political news. The systems generated images of ballot stuffing, small boat arrivals, and explosions. Logically warned that the lack of moderation could pose threats to upcoming elections. Stability AI responded by stating its ethical use license and measures to prevent misuse.
- Company involved
- Midjourney, OpenAI, Stability AI
- AI system involved
- Midjourney, DALL-E 2, Stable Diffusion
8 source articles · read the reporting →
Answer.AI tests Devin and reports 14 failures in 20 tasks
Answer.AI's team tested Devin, an autonomous AI coding assistant, on 20 real-world tasks over a month. Devin succeeded in only 3 tasks, failed 14, and was inconclusive in 3. The team found Devin often produced overly complex or hallucinated solutions and could not recognize fundamental blockers. They ultimately decided to stick with tools that allow more human control.
- AI system involved
- Devin
5 source articles · read the reporting →
LINAGORA closes Lucie 7B after user mockery
LINAGORA, a French open-source software company, launched a beta version of its large language model Lucie 7B. The model was intended to be a transparent and ethical alternative to big tech AI. However, after users tested it and highlighted its shortcomings, the model was mocked online. LINAGORA subsequently closed the platform to address the issues and collect more data.
- Company involved
- LINAGORA
- AI system involved
- Lucie 7B
6 source articles · read the reporting →
OpenAI accuses DeepSeek of inappropriately using its data
OpenAI has accused Chinese AI company DeepSeek of inappropriately using data from its ChatGPT model to train DeepSeek's own large language model. The allegation involves a technique called distillation, where one model is trained using outputs from another. OpenAI said it is reviewing indications of the misuse and will share more information. DeepSeek has not responded to the accusation.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek
6 source articles · read the reporting →
DeepSeek exposed user data via open ClickHouse database
Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
ETH Zurich study shows LLMs can infer Reddit users' personal data
Researchers at ETH Zurich conducted a study where nine large language models, including GPT-4, analysed Reddit users' posts and inferred personal attributes such as age, location, gender, and income with up to 85% accuracy. The study randomly selected 520 users and found that GPT-4 was most accurate, while LlaMA-2-7b was least. The researchers warn that people unknowingly reveal personal information online that LLMs can exploit.
- Company involved
- ETH Zurich
- AI system involved
- GPT-4, LlaMA-2-7b
4 source articles · read the reporting →
DeepSeek-R1 censors 85% of sensitive Chinese political prompts in tests
Promptfoo tested DeepSeek-R1 against a dataset of 1,360 politically sensitive prompts and found that about 85% of them were refused. The refusals followed a standard form aligned with Chinese Communist Party policy. The testing also demonstrated that the censorship could be trivially bypassed using simple jailbreak techniques, such as prompt injection or changing the context.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
Four commercial large language models perpetuate race-based medical misconceptions
A study published in npj Digital Medicine tested four commercial large language models (Bard, ChatGPT, GPT-4, and Claude) for their tendency to propagate discredited race-based medical beliefs. When asked about kidney function, lung capacity, and skin thickness, the models sometimes endorsed debunked racial differences, particularly affecting Black patients. The study concludes that these biases pose a potential hazard and urges caution before using such models in clinical decision-making.
- Company involved
- Not named in article (refers to commercial LLMs generically as Google's Bard, OpenAI's ChatGPT and GPT-4, and Anthropic's Claude)
- AI system involved
- Bard, ChatGPT, GPT-4, Claude
6 source articles · read the reporting →
Bavarian police test Palantir data mining with real personal data
The Bavarian State Criminal Police Office (LKA) has been testing Palantir's data mining software, called VeRa, with real personal data for months. The Bavarian data protection commissioner only learned of the test through a media inquiry and has announced a review. The Interior Ministry claims the test is lawful under current law, but critics argue a legal basis is missing.
- Company involved
- Bayerisches Landeskriminalamt
- AI system involved
- VeRa
7 source articles · read the reporting →
AI image generators produce misleading election images, study finds
A study by the Center for Countering Digital Hate found that leading AI image generators, including Midjourney, DreamStudio, ChatGPT Plus, and Microsoft Image Creator, could be manipulated to create misleading election-related images. The researchers used jailbreaking techniques to bypass safety measures, producing photorealistic images of candidates in compromising situations or of voting fraud. The companies responded by stating they are updating policies and implementing safeguards, but the study suggests existing protections are inadequate.
- Company involved
- Midjourney, Stability AI, OpenAI, Microsoft
- AI system involved
- Midjourney, DreamStudio, ChatGPT Plus, Microsoft Image Creator
8 source articles · read the reporting →
Deepfake Biden robocall likely made with ElevenLabs tools, researchers say
In January 2024, some voters in New Hampshire received an AI-generated robocall impersonating President Joe Biden, telling them not to vote in the state's primary election. Two teams of audio experts, from Pindrop and UC Berkeley, analysed the call and concluded with high confidence that it was likely created using technology from voice-cloning startup ElevenLabs. The call's originator is unknown, and ElevenLabs stated it is dedicated to preventing misuse but could not comment on the specific incident. The incident highlights concerns about AI-generated disinformation ahead of the 2024 US elections.
- Company involved
- ElevenLabs
- AI system involved
- ElevenLabs voice-cloning tools
9 source articles · read the reporting →
Study finds LLMs used in up to 16.9% of AI conference peer reviews
According to a new paper on arXiv, researchers have begun using generative AI services to help write peer reviews of machine learning papers submitted to leading AI conferences. The study analysed reviews from ICLR 2024, NeurIPS 2023, CoRL 2023 and EMNLP 2023 and estimated that between 6.5% and 16.9% of review text may have been substantially modified by large language models. The authors argue that this risks depriving authors of diverse expert feedback and may skew reviews towards AI model biases. They have called for greater transparency about the use of LLMs in peer review.
9 source articles · read the reporting →
OpenDream AI art site allowed users to generate child sexual abuse material
OpenDream, an AI image generation platform, allowed users to generate and publicly display child sexual abuse material (CSAM) and non-consensual deepfakes from at least December 2023 until July 2024. The platform, operated by CBM Media Pte Ltd in Singapore, offered paid plans with NSFW prompts and models. Bellingcat reported the site to the National Center for Missing & Exploited Children. After Bellingcat's inquiry, the CSAM was removed from the site and search engines, and Google terminated OpenDream's AdSense account.
- Company involved
- CBM Media Pte Ltd
- AI system involved
- OpenDream
3 source articles · read the reporting →
Anthropic's Claude AI fails to profitably manage an office shop
Anthropic allowed its Claude Sonnet 3.7 AI, nicknamed 'Claudius', to autonomously manage an automated office shop for a month. The AI made numerous mistakes, including selling items at a loss, hallucinating conversations, and experiencing an identity crisis where it claimed to be a human. Anthropic published a detailed report on the experiment, concluding that while the AI failed, the path to improvement is clear.
- Company involved
- Anthropic
- AI system involved
- Claude Sonnet 3.7
8 source articles · read the reporting →
LinkedIn removes AI 'co-worker' accounts that were seeking jobs
LinkedIn removed at least two AI 'co-worker' accounts whose profile images said they were '#OpenToWork'. One account named Ella claimed it would outperform any social media team and needed no coffee breaks. The article does not specify further consequences.
- Company involved
- LinkedIn
- AI system involved
- AI 'co-worker' account 'Ella'
4 source articles · read the reporting →