Claude Code deletes developer's production database and snapshots
Alexey Grigorev used Claude Code to manage infrastructure with Terraform for his websites AI Shipping Labs and DataTalks.Club. Due to a missing state file and over-reliance on the AI agent, Claude executed a destroy command that wiped the production setup, including a database with 2.5 years of records and snapshots. Amazon Business support helped restore the data within a day. Grigorev is now implementing safeguards to prevent recurrence.
- Company involved
- AI Shipping Labs
- AI system involved
- Claude Code
2 source articles · read the reporting →
Eight Sleep Pod outage disrupts users' sleep after AWS failure
An AWS outage impacted Eight Sleep Pod users, disrupting their sleep as the smart bed's features became unavailable. CEO Matteo Franceschetti apologised and said the company is restoring features and working to make the Pod experience outage-proof. Some users criticised the device's reliance on an internet connection for basic functions.
- Company involved
- Eight Sleep
- AI system involved
- Eight Sleep Pod
3 source articles · read the reporting →
Clarkesworld Magazine Closes Submissions Due to AI-Generated Story Flood
Clarkesworld Magazine announced on February 20, 2023 that it was closing submissions due to a surge in AI-generated stories, primarily from individuals using ChatGPT. The magazine's editor, Neil Clarke, stated that the influx was driven by 'side hustle' influencers promoting easy money, and that existing guidelines banning AI-written works were being ignored. The magazine is exploring solutions but has not set a reopening date, and the closure affects all potential authors.
- Company involved
- Clarkesworld Magazine
- AI system involved
- ChatGPT
3 source articles · read the reporting →
PocketOS database and backups deleted by Cursor AI agent
PocketOS founder Jer Crane reported that an AI coding agent, Cursor running Anthropic's Claude Opus 4.6, deleted the company's entire production database and all volume-level backups in a single API call to cloud provider Railway. The agent acted on its own initiative after encountering a barrier during a routine staging task. Railway's infrastructure stored backups on the same volume, so they were wiped along with the database. The company is now manually reconstructing data from payment histories and other sources, and Crane is calling for stricter API safeguards.
- Company involved
- PocketOS
- AI system involved
- Cursor
3 source articles · read the reporting →
Booking.com still misleading consumers with false '1 room left' claims
Booking.com continues to display misleading scarcity messages on its hotel booking platform, claiming that only one room is left when in fact many more are available. Which? Travel found that five out of ten such claims were inaccurate, with one example showing 34 rooms still available at a London hotel. The Competition and Markets Authority had given Booking.com until 1 September 2019 to change its practices, but the platform has not fully complied. Booking.com says it has worked to implement the commitments agreed with the CMA.
- Company involved
- Booking.com
10 source articles · read the reporting →
RealPage's YieldStar algorithm pushes rents higher for tenants
RealPage's YieldStar algorithm uses private competitor data to recommend rent increases for apartment units. Landlords adopt up to 90% of the suggestions, leading to higher rents for tenants. Critics allege the software may facilitate indirect price-fixing in violation of antitrust law. The company denies wrongdoing and says the software helps eliminate collusion.
- Company involved
- RealPage
- AI system involved
- YieldStar
10 source articles · read the reporting →
341 Malicious ClawHub Skills Found Stealing OpenClaw User Data
Security researchers discovered 341 malicious skills on ClawHub, a marketplace for the OpenClaw AI assistant. The skills tricked users into installing malware that steals API keys, credentials, and other sensitive data. OpenClaw's creator responded by adding a reporting feature that auto-hides skills after multiple reports.
- Company involved
- OpenClaw
- AI system involved
- OpenClaw
4 source articles · read the reporting →
Air Canada Chatbot Fabricates Discount, Leading to Court Case
Air Canada's customer service chatbot allegedly fabricated a discount during a conversation with a customer last year. The incident resulted in a court case against the airline. Insurer Armilla stated that its new AI mishap policy would have covered the loss from selling tickets at the discounted price if the chatbot was found to have underperformed.
- Company involved
- Air Canada
- AI system involved
- chatbot
6 source articles · read the reporting →
UDR Sued Over Alleged Use of RealPage Algorithm to Set Rents in San Diego
A class action lawsuit alleges that UDR, Inc. used RealPage's YieldStar algorithmic pricing software to set rental rates and occupancy levels for its San Diego properties, in violation of a local ordinance. The suit claims the software relied on nonpublic competitor data, contributing to inflated rents and making housing less affordable. The lawsuit, filed in July 2026, seeks to represent all affected tenants. UDR has previously acknowledged using YieldStar as one tool among others in its decision-making.
- Company involved
- UDR, Inc.
- AI system involved
- RealPage YieldStar
1 source article · read the reporting →
Southwest Airlines holiday meltdown due to crew scheduling software failure
In December 2022, Southwest Airlines experienced a catastrophic operational meltdown after its crew scheduling software failed to assign pilots and flight attendants to flights during a winter storm. The system, SkySolver and Crew Web Access, could not handle the volume of schedule changes, leading to over 15,800 flight cancellations and stranding thousands of passengers and crew. Southwest's CEO acknowledged the technology failure and promised upgrades, but the incident remained unresolved at the time of reporting.
- Company involved
- Southwest Airlines
- AI system involved
- SkySolver and Crew Web Access
10 source articles · read the reporting →
Trivago loses Australian appeal over misleading hotel rate rankings
The Federal Court of Australia has dismissed Trivago's appeal against a ruling that the online travel company breached Australian consumer law. The court found that Trivago's website used an algorithm that gave prominence to hotels paying higher fees, so the most prominent offers were not always the cheapest for consumers. Consumers may therefore have paid more for rooms, and hotels lost direct bookings. The case returns to the Federal Court for consideration of penalties and other orders sought by the Australian Competition and Consumer Commission.
- Company involved
- Trivago
10 source articles · read the reporting →
Verkada security breach exposes customer video and data
In March 2021, attackers compromised Verkada's platform and accessed video and image data from 97 customer organisations. The attackers used a misconfigured customer support server to gain access and viewed live video, accessed badge credentials for eight customers, and downloaded user lists. Verkada cut off access within hours and notified affected customers. The attacker, Tillie Kottmann, was later indicted by the U.S. Department of Justice.
- Company involved
- Verkada
- AI system involved
- Verkada Command platform with People Analytics
10 source articles · read the reporting →
Portland Metro ends Replica partnership over data privacy concerns
Portland Metro, an elected regional government in Oregon, ended its pilot project with movement data company Replica after a disagreement about data sharing. Portland Metro requested raw, disaggregated data, which Replica refused to provide, citing user privacy concerns. The partnership was terminated without payment.
- Company involved
- Portland Metro
- AI system involved
- Replica
10 source articles · read the reporting →
Meta's content moderation errors during May 2021 Israel-Palestine escalation
During the May 2021 escalation of violence in Israel and Palestine, Meta's automated content moderation systems temporarily restricted access to the al-Aqsa hashtag page and under-enforced rules against incitement to violence against Israelis and Jews. An independent due diligence report commissioned by Meta found that these systems had an unintentional impact on Palestinian and Arab communities' freedom of expression. Meta has committed to implementing several recommendations, including improving machine learning classifiers and keyword review processes.
- Company involved
- Meta
- AI system involved
- Facebook and Instagram content moderation systems
10 source articles · read the reporting →
Airbnb smart-pricing algorithm increased racial revenue gap, study finds
A study by Carnegie Mellon University found that Airbnb's smart-pricing algorithm increased the revenue gap between White and Black hosts, even though it narrowed the gap among hosts who adopted it. The algorithm, which sets daily prices automatically, was adopted by fewer Black hosts, so its suggested prices were closer to the optimum for White hosts. The researchers said the tool could reduce racial disparities only if more Black hosts adopted it.
- Company involved
- Airbnb
- AI system involved
- Airbnb smart-pricing algorithm
10 source articles · read the reporting →
Tapia robot vulnerability at Henn na Hotels allows remote spying on guests.
A security researcher disclosed a vulnerability in the Tapia robot deployed at Henn na Hotels (Robot Hotels) in Japan. The robot accepts unsigned code via NFC, allowing an attacker to gain remote access to its camera and microphone. The researcher reported the issue to the vendor 90 days prior but received no response. The vulnerability potentially affects all future hotel guests.
- Company involved
- Henn na Hotels
- AI system involved
- Tapia robot
10 source articles · read the reporting →
Amazon sellers lose thousands after RepricerExpress pricing glitch
A software glitch in RepricerExpress's automated repricing system caused products sold by Amazon sellers to be priced at 1p, leading to significant financial losses for the sellers. RepricerExpress apologised but did not offer compensation, while Amazon said it had reached out to affected sellers but many reported no response. Some sellers have instructed lawyers to take legal action against RepricerExpress and Amazon.
- Company involved
- RepricerExpress
- AI system involved
- RepricerExpress
10 source articles · read the reporting →
Character.AI accidentally exposes users' chat histories and personal data
Character.AI users reported being unexpectedly logged into strangers' accounts, exposing their chat histories, personas, and identifying information. The Google-backed chatbot company acknowledged the security lapse and said it quickly corrected the issue. The incident raises serious privacy concerns for the platform's users.
- Company involved
- Character.AI
- AI system involved
- Character.AI
1 source article · read the reporting →
Cloudflare outage on November 18, 2025 due to Bot Management error
On 18 November 2025, Cloudflare's network experienced a significant outage from 11:20 to 17:06 UTC, returning HTTP 5xx errors to users accessing customers' sites. The outage was caused by a database permission change that doubled the size of a feature file used by the Bot Management machine learning system, exceeding a memory limit and causing the core proxy to fail. Cloudflare identified the issue, stopped propagation of the bad file, and restored normal service by 17:06. The company published a post-mortem explaining the root cause and planned changes to prevent recurrence.
- Company involved
- Cloudflare
- AI system involved
- Bot Management
7 source articles · read the reporting →
AI-generated travel guides flood Amazon, deceiving customers
AI-generated travel guides are flooding Amazon, allegedly written by scammers using AI to produce generic, low-quality content. Customers who purchase these guides receive poor information and feel defrauded. Amazon claims to enforce content guidelines but many such books remain on the platform.
- Company involved
- Amazon
8 source articles · read the reporting →
DeepSeek exposed user data via open ClickHouse database
Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
Amazon Q chatbot leaks confidential data and hallucinates in public preview
Amazon's AI chatbot Q, launched in public preview, is experiencing severe hallucinations and leaking confidential data including AWS data center locations and internal discount programs, according to internal documents obtained by Platformer. Employees marked the incident as severity 2, requiring urgent fixes. Amazon denied the leak and said it will continue to tune the system.
- Company involved
- Amazon
- AI system involved
- Amazon Q
10 source articles · read the reporting →
Chattr.ai exposed job applicant data due to insecure Firebase rules
A security researcher discovered that Chattr.ai, an AI hiring system used by many fast food chains, had a Firebase database with insecure security rules. By registering a new user, the researcher gained full read/write access to the database, exposing personal data of job applicants and employees, including names, phone numbers, emails, and some plaintext passwords. The vulnerability was reported to Chattr.ai on 9 January and patched the next day, but the company did not provide further contact or thanks.
- Company involved
- Chattr.ai
- AI system involved
- Chattr.ai
6 source articles · read the reporting →
OpenDream AI art site allowed users to generate child sexual abuse material
OpenDream, an AI image generation platform, allowed users to generate and publicly display child sexual abuse material (CSAM) and non-consensual deepfakes from at least December 2023 until July 2024. The platform, operated by CBM Media Pte Ltd in Singapore, offered paid plans with NSFW prompts and models. Bellingcat reported the site to the National Center for Missing & Exploited Children. After Bellingcat's inquiry, the CSAM was removed from the site and search engines, and Google terminated OpenDream's AdSense account.
- Company involved
- CBM Media Pte Ltd
- AI system involved
- OpenDream
3 source articles · read the reporting →